Introducing Gemini 3.5 Flash Cyber
Google introduced Gemini 3.5 Flash Cyber, a lightweight cybersecurity model designed to detect and patch software vulnerabilities efficiently. The model will be available to governments and trusted partners via CodeMender in a limited pilot program, with plans for broader expansion.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
Google has developed Gemini 3.5 Flash Cyber, a lightweight cybersecurity model built on the 3.5 Flash architecture and fine-tuned to identify, validate, and patch software vulnerabilities more effectively than standard Flash models. The model is positioned as a cost-efficient alternative to larger, more expensive cybersecurity solutions, addressing the growing challenge of AI-driven vulnerability discovery outpacing defensive measures. Google emphasizes its practical application in automated security workflows, particularly for large codebases where rapid, repeated analysis is required.
The model will be introduced through a limited-access pilot program exclusively available to governments and trusted partners via CodeMender, Google’s code security agent. This deployment strategy aims to provide frontline defenders with early access to vulnerability detection capabilities while mitigating risks of misuse. Additionally, CodeMender’s core features will be made available to customers through the Gemini Enterprise Agent Platform using generally available Gemini models, expanding accessibility beyond the pilot program.
Gemini 3.5 Flash Cyber demonstrated strong performance in benchmarks, including CyberGym, where it achieved competitive results against significantly larger models by leveraging multiple low-cost invocations. In independent tests by Google’s Big Sleep team, the model surpassed mainline 3.5 Flash and 3.6 Flash in identifying critical vulnerabilities in complex codebases like Chrome and Safari. On Google Chrome’s production commit scanning pipeline, it showed a significant improvement over 3.5 Flash, discovering 55 unique confirmed issues compared to 47 by 3.5 Flash and 36 by Claude Opus 4.6.
Google reports that Gemini 3.5 Flash Cyber is already operational in internal codebases, including Chrome, Android, Cloud, Ads, and YouTube, where it has enabled rapid vulnerability discovery. For example, Google’s Cloud Vulnerability Research team used the model to uncover remote code execution vulnerabilities and a memory-corruption issue in a sensitive production service within two hours. Early feedback from external testers, including Wiz and Cloud CISO Security Engineering, confirms the model’s enhanced capability over mainline 3.5 Flash.