Introducing Gemini 3.5 Flash Cyber
Google introduces Gemini 3.5 Flash Cyber, a lightweight cybersecurity model to find and patch vulnerabilities.
Google has launched Gemini 3.5 Flash Cyber, a lightweight cybersecurity model designed to quickly and efficiently find, validate, and patch software vulnerabilities. This new model is built on top of Google's existing 3.5 Flash model and is fine-tuned specifically for cybersecurity tasks. By leveraging the cost-efficient and high-capacity performance of 3.5 Flash, Gemini 3.5 Flash Cyber offers a more affordable alternative to larger, pricier cybersecurity models.
As part of a limited-access pilot program, the model will initially be available exclusively to governments and trusted partners through Google's CodeMender platform. This restricted rollout aims to give frontline security defenders an advantage in identifying and fixing critical vulnerabilities before they can be exploited, while also minimizing the risk of broader misuse.
Gemini 3.5 Flash Cyber's strength lies in its ability to scan large codebases and analyze numerous code paths, making it particularly well-suited for finding vulnerabilities within large, complex systems. By invoking the model multiple times, CodeMender can analyze extensive codebases, resulting in the discovery of a higher number of unique vulnerabilities compared to mainline 3.5 Flash and other competing models like Claude Opus 4.6.
In internal Google codebases, such as Chrome, Android, Cloud, Ads, and YouTube, Gemini 3.5 Flash Cyber has demonstrated its capability to find and fix vulnerabilities rapidly. For instance, Google's Cloud Vulnerability Research team used the model to uncover remote code execution vulnerabilities in public APIs and memory-corruption issues in sensitive production services within just two hours.
Moreover, early feedback from Wiz and Cloud CISO Security Engineering testers confirms that Gemini 3.5 Flash Cyber offers a significant capability improvement over the mainline 3.5 Flash model.
Written by urgent.news from Google DeepMind's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.