MeshioMeshio
News

Google targets scalable vulnerability hunting with Gemini 3.5 Flash Cyber

Google’s new lightweight model is designed to help security agents find, validate and patch software flaws at a lower cost.

Meshio Newsroom
Meshio NewsroomAug 24, 2026
Google targets scalable vulnerability hunting with Gemini 3.5 Flash Cyber

Google has introduced Gemini 3.5 Flash Cyber, a cybersecurity-focused model built on Gemini 3.5 Flash. The company says it is fine-tuned to discover, verify and patch vulnerabilities, with an emphasis on speed, affordability and large-scale code analysis.

The model is designed for CodeMender, Google’s code-security agent. Rather than relying on one expensive model call, CodeMender can invoke Flash Cyber repeatedly to explore more execution paths and combine the results into a final report. That architecture could make continuous repository scans, commit checks and pre-launch security reviews more practical for teams operating at scale.

Reported security results

Google says Flash Cyber delivered competitive results against substantially larger cybersecurity models on the CyberGym benchmark when CodeMender used up to five model calls per report. In an evaluation of the V8 JavaScript engine, it reportedly identified 55 unique confirmed issues, compared with 47 for Gemini 3.5 Flash and 36 for Claude Opus 4.6. Google also reports gains in tests involving Chrome production commits and complex codebases.

The company says the model is already being used through CodeMender across internal projects including Chrome, Android, Cloud, Ads and YouTube. In one reported two-hour exercise, it found remote-code-execution flaws in public APIs and a memory-corruption issue in a production service, then generated an exploit that bypassed common mitigations.

Because vulnerability discovery is dual-use, access will initially be limited. Google plans to offer Flash Cyber through a pilot for governments and trusted partners via CodeMender, with broader expansion over time. Separately, CodeMender’s underlying capabilities are being made available to customers using generally available Gemini models through the Gemini Enterprise Agent Platform.

For AI tool builders, the announcement highlights a practical design pattern: smaller, specialized models can deliver broader search coverage when orchestrated across many calls, potentially lowering the cost of security automation.

Source: Google DeepMind Blog

Comments

Log in to join the discussion