
The company said it has invested in cybersecurity research for years, including automated vulnerability discovery through CodeMender, its code security agent that can detect and fix critical software flaws. However, as AI systems become increasingly capable of discovering , Gemini 3.5 Flash Cyber has been fine-tuned specifically to locate, verify, and remediate vulnerabilities more effectively than Gemini's standard Flash models. Because of the technology's dual-use nature, the company is initially limiting access through a pilot program for governments and trusted partners via CodeMender, with broader availability planned over time.
Google also confirmed that CodeMender's core capabilities will be made available through generally available Gemini models on the Gemini Enterprise Agent Platform.
Flash Cyber Improves Large-scale Code Analysis
A major challenge in , CodeMender invokes Flash Cyber multiple times, allowing sub-agents to inspect significantly more code paths before generating one consolidated report.
Google said the model's speed and lower operating cost make it suitable for continuous code scanning, software launch processes, and commit-scanning pipelines at scale.
Benchmark Results Show Competitive Performance
Google evaluated Gemini 3.5 Flash discovery in complex projects such as Chrome and Safari without safety guardrails.
In Chrome's production commit-scanning pipeline, where vulnerabilities remained undisclosed to prevent benchmark contamination, Flash Cyber again delivered a significant improvement over Gemini 3.5 Flash. Google added that competitor models released after Opus 4.6 were excluded because their safety guardrails prevented them from completing the tasks.
Testing on the V8 JavaScript Engine found 55 unique confirmed vulnerabilities with exploit capable of bypassing Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X).
Google added that early feedback from Wiz and Cloud CISO as key training assets supporting its cybersecurity models.
SOCIAL SHARE CARD GENERATOR