Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
17:09 · July 21, 2026 · Hacker News AI Section

Google's DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that's designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot
Summary
Google DeepMind has released Gemini 3.5 Flash Cyber, a specialized model built on the 3.5 Flash foundation and tuned for vulnerability discovery, validation, and patching. The lightweight design serves as a cost-efficient alternative to larger dedicated security models, allowing repeated high-speed calls that let an agent examine more code paths without proportional increases in expense.
Initial access is limited to a pilot through CodeMender, the AI-powered agent Google introduced in October 2025. The model is available only to governments and trusted partners, a deliberate restriction intended to give defenders an early advantage while limiting broader misuse of its dual-use capabilities. CodeMender runs the model inside controlled guardrails that enable defensive tasks such as forensic analysis while blocking offensive operations.
In internal evaluations the model outperformed both Gemini 3.5 Flash and 3.6 Flash on new vulnerability detection. On the V8 JavaScript engine it identified 55 unique confirmed issues under a fixed invocation budget, compared with 47 for 3.5 Flash and 36 for Anthropic Claude Opus 4.6, including ten issues missed by the other systems. It has also produced a fully reliable remote-code-execution exploit that bypassed standard mitigations including address-space layout randomization.
Google plans to extend the underlying CodeMender capabilities to enterprise customers through the Gemini Enterprise Agent Platform and to add red-teaming and end-to-end defense features over time.
Why it matters
This article is highly relevant for Dutch security professionals as it introduces a state-of-the-art AI tool for automated vulnerability discovery and patching. Given the strict EU regulatory landscape (like NIS2 and the Cyber Resilience Act), leveraging such AI capabilities will be critical for Dutch enterprises and government bodies to proactively secure software supply chains.










