Google DeepMind unveils a small cyber model built to find and fix code flaws
Google DeepMind introduced Gemini 3.5 Flash Cyber on July 21, 2026, a lightweight cybersecurity model built on Gemini 3.5 Flash and fine-tuned to find, validate, and patch software vulnerabilities. It will be available only to governments and trusted partners through the CodeMender tool in a limited-access pilot, while related capabilities reach other customers via the Gemini Enterprise Agent Platform.
On Google's reported benchmarks, the model outperformed its mainline counterparts. On a test against the V8 JavaScript engine it found 55 unique confirmed issues, versus 47 for mainline 3.5 Flash and 36 for Claude Opus 4.6, including 10 issues the other two models missed. Google says its Cloud Vulnerability Research team used the model in two hours to find remote code execution flaws in public APIs and a memory-corruption bug in a production service, and that it generated an exploit bypassing common memory protections. CodeMender can call the model up to five times for a single report on the CyberGym benchmark.
Cheaper, automated vulnerability discovery could shift the balance toward defenders, letting smaller teams audit and patch code they could never afford to review by hand. That is the abundance case: security work that once required scarce expert labor becoming more scalable.
The honest caveats are large. This is Google promoting its own product, competitor scores are self-reported, and some evaluations ran without safety guardrails. Google notes newer rival models refuse these tasks entirely. The same capability that patches flaws also writes working exploits, so who holds access matters.
Source: Google DeepMind
MANY MINDED