OFICIAL Google DeepMind Blog

Introducing Gemini 3.5 Flash Cyber — Google DeepMind

What happened
Based on Google DeepMind Blog · Jul 17, 2026

Google DeepMind introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model designed to detect and patch software vulnerabilities efficiently, available initially to governments and trusted partners via a pilot program.

Key points
·
Google has invested in cybersecurity for years, pioneering automated vulnerability discovery to secure the world’s codebases.
·
Tools like CodeMender, its code security agent, can automatically find and fix critical software vulnerabilities.
·
But as AI agents become more capable at finding vulnerabilities faster than defenders can fix them, addressing this global threat requires a highly capable, affordable, and scalable approach.
·
Flash’s performance and efficiency makes it an ideal foundation for its cybersecurity model efforts.

Google DeepMind has developed Gemini 3.5 Flash Cyber, a specialized model built on the 3.5 Flash architecture and fine-tuned for cybersecurity tasks. The model is engineered to identify, validate, and patch software vulnerabilities more effectively than its mainline counterparts, addressing the growing challenge of AI-driven threats. Its lightweight design ensures cost efficiency while maintaining high performance, making it suitable for large-scale deployment. The model will be accessible through a limited-access pilot program for governments and trusted partners via CodeMender, with plans for gradual expansion.

CodeMender, Google’s automated vulnerability discovery tool, integrates Gemini 3.5 Flash Cyber to enhance its ability to scan extensive codebases and analyze multiple execution paths. The model’s speed and affordability enable frequent scans and real-time vulnerability detection, reducing bottlenecks in security workflows. In testing, Gemini 3.5 Flash Cyber demonstrated competitive performance on the CyberGym benchmark, outperforming larger models in identifying critical vulnerabilities in complex systems like Chrome and Safari. Its ability to discover unique issues—such as 55 confirmed vulnerabilities in the V8 JavaScript Engine—highlights its effectiveness compared to mainline models.

Google has tested Gemini 3.5 Flash Cyber across multiple benchmarks, including real-world scenarios like Chrome’s production commit scanning pipeline. The model significantly outperformed mainline 3.5 Flash and other competitors, such as Claude Opus 4.6, in discovering unique vulnerabilities. Its capacity to scale invocations allows it to uncover new code paths and vulnerabilities continuously. Internally, Google’s Cloud Vulnerability Research team used the model to identify critical vulnerabilities, including remote code execution flaws, in record time, demonstrating its practical impact on security operations.

The model’s development leverages Google’s extensive cybersecurity resources, including OSV.dev and OSS-Fuzz, which provide data on over 700,000 open-source vulnerabilities. By training on real-world security tasks and industry-standard tools, Gemini 3.5 Flash Cyber is designed to assist defenders in securing software at scale. The architecture, powered by CodeMender, offers a scalable and affordable solution for vulnerability detection and patching, with plans to expand availability beyond the initial pilot program.

Original source → Deals on Clipraptor.com →