Google DeepMind Unveils Gemini 3.5 Flash Cyber: An AI for Rapid Vulnerability Discovery and Patching
Google DeepMind has announced **Gemini 3.5 Flash Cyber**, a specialized AI model designed to accelerate the discovery, validation, and patching of software vulnerabilities. This new model, built on **3.5 Flash**, will be exclusively available to governments and trusted partners through a limited-access pilot program via **CodeMender**, an AI-powered agent for cybersecurity.

**Google DeepMind** on Tuesday unveiled **Gemini 3.5 Flash Cyber**, a new artificial intelligence (AI) model engineered for efficient vulnerability management. This specialized AI is designed to identify, validate, and patch software weaknesses at an accelerated pace.
### Exclusive Access for Critical Defense
The tech giant confirmed that **Gemini 3.5 Flash Cyber** will initially be available only to governments and trusted partners. This access will be facilitated through **CodeMender**, an AI-powered agent for vulnerability discovery and patching that **Google** first introduced in October 2025. A **DeepMind** spokesperson indicated future plans to expand the model's capabilities to include red-teaming features and comprehensive enterprise defense solutions.
### Cost-Effective and Highly Capable
**DeepMind** highlights the lightweight nature of **3.5 Flash Cyber**, positioning it as a cost-efficient yet highly capable alternative to larger, more expensive cybersecurity-focused AI models. Its integration with **CodeMender** allows for multiple, high-speed, low-cost invocations, enabling the AI agent to scan more code paths and uncover a greater number of vulnerabilities.
This release coincides with the introduction of **Gemini 3.6 Flash** and **3.5 Flash-Lite**, models optimized for improved coding, knowledge work, and low-latency, multimodal performance, respectively.
### A Deliberate Deployment Strategy
**Raluca Ada Popa**, **DeepMind's Gemini Security Lead**, and **Four Flynn**, Vice President of Security and Privacy at **DeepMind**, emphasized a cautious deployment approach. In a blog post, they stated, "Given the dual-use nature of this technology, we have taken an intentional approach to how we deploy **3.5 Flash Cyber**."
They explained that the limited-access pilot program aims to provide frontline defenders with a significant advantage in identifying and remediating critical vulnerabilities before exploitation, while simultaneously mitigating potential misuse.
### Guardrails for Responsible AI
Crucially, since **3.5 Flash Cyber** operates exclusively within **CodeMender**, it allows for the configuration of specific guardrails. These guardrails ensure that only the AI agent's defensive functions are enabled, while other cyber activities are disabled. This proactive measure prevents scenarios where an AI model might refuse to assist defenders with tasks like AI-assisted forensic analysis.

### Outperforming Existing Models
Internal evaluations by **DeepMind** reveal that **3.5 Flash Cyber** significantly outperforms **Gemini 3.5 Flash** and **3.6 Flash** in discovering new vulnerabilities within codebases. Stress-testing on complex projects such as **Google Chrome** and **Apple Safari** further demonstrated its superior performance compared to **Gemini 3.5 Flash**, **3.6 Flash**, and **Anthropic Claude Opus 4.6**.
"**3.5 Flash Cyber** consistently discovered more unique vulnerabilities compared with **3.5 Flash** and **Claude Opus 4.6**," the report noted. When tested on the highly complex **V8 JavaScript Engine**, **Gemini 3.5 Flash Cyber** identified 55 unique confirmed issues, surpassing **Gemini 3.5 Flash** (47 issues) and **Opus 4.6** (36 issues), including 10 vulnerabilities that no other model detected.
Similar to efforts by **Anthropic** and **OpenAI**, **Google** has deployed **3.5 Flash Cyber** to uncover critical flaws, including remote code execution vulnerabilities in public APIs and memory-corruption vulnerabilities in sensitive production services. The model also successfully generated a 100% reliable remote-code execution exploit that bypassed standard mitigation techniques like **Address Space Layout Randomization (ASLR)** and **Write XOR Execute (W^X)**.
**Google** is also making **CodeMender's** foundational capabilities accessible to customers through generally available **Gemini** models via the **Gemini Enterprise Agent Platform**.
"By powering **CodeMender** with **3.5 Flash Cyber**, we're providing a highly capable, scalable, and affordable architecture designed to help more defenders secure software," **Google** stated.