Google DeepMind
AI · Cybersecurity
Google DeepMind launches Gemini 3.5 Flash Cyber for vulnerability patching
July 21, 2026
Calling a lightweight model many times cheaply lets security teams scan far more code paths than one expensive frontier pass could.
- Google DeepMind unveiled Gemini 3.5 Flash Cyber, a specialized model built on Gemini 3.5 Flash that finds, validates, and patches software vulnerabilities, integrated into its CodeMender security agent.
- CodeMender, first introduced by Google DeepMind in October 2025 as a research project, now runs proof-of-concept exploits in sandboxes and delivers tested code fixes directly into development pipelines.
- The model is available first to governments and trusted partners in preview via the Gemini Enterprise Agent Platform and Google Cloud's AI Threat Defense.
- Testing on the V8 JavaScript engine, 3.5 Flash Cyber found 55 unique confirmed vulnerabilities versus 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6, including 10 issues the others missed.
- Google positions the model as a cheaper alternative to compute-heavy rivals like Anthropic's Mythos 5, which costs twice as much as Claude Opus 4.8 to run and is used by Microsoft for security checks.
- As AI increasingly powers both attackers hunting flaws and defenders patching them, the economics of running many cheap model calls versus few expensive ones is becoming a decisive factor in cybersecurity.