Google has recently launched the Gemini 3.5 Flash Cyber, particularly as a cheaper rival to large scale security models such as Anthropic and Open AI. It scans, finds and patches software vulnerabilities automatically.
Features and reason behind its creation
The model expands Google’s existing automated defence work, building on its internal code security agent, CodeMender. Gemini 3.5 Flash Cyber is currently limited to a restricted pilot programme, available only to government bodies and select enterprise partners through CodeMender. Google is going for a careful rollout.
Also Read | Can AI medical advice be dangerous? Lawsuit claims ChatGPT left man critically ill
Gemini 3.5 Flash Cyber’s lightweight design lets it run multiple fat, low-cost scans across large codebases instead of one expensive pass. CodeMender uses 3.5 Flash Cyber repeatedly across different sections of code to analyse vulnerabilities, then combines the results into a single security report.

Google says that because of being cheap and fast to run, the model can be built directly into regular software updates, daily code commits, and time-sensitive product launches without adding significant cost.
The model is running across several production systems of Google such as Chrome, Android, Google Cloud, Ads, and YouTube. After sharing results from the CyberGym benchmark, Google proved that running the new model up to five times per task through CodeMender, it delivered results competitive with much larger and costlier models.
Trial results
The model worked fast during a trial by Google’s Cloud Vulnerability Research team. Google said that within two hours, 3.5 Flash Cyber found remote code execution flaws in public APIs and identified a memory-corruption vulnerability in a sensitive production service, before building a fully working exploit proof-of-concept that successfully got past standard memory protections.
Also Read | ChatGPT down? Thousands of Indian users hit by sudden OpenAI outage
The specialised model performed significantly better than the standard, mainline version of Gemini 3.5 Flash, according to early testers from cybersecurity firm Wiz, along with Google’s Cloud CISO Security Engineering team.
FAQs
What is the new model of Google to scan software vulnerabilities?
The new model of Google to scan software vulnerabilities is Gemini 3.5 Flash Cyber.
How is Google rolling out the new model?
Google is rolling out the new model carefully and it is currently limited to a restricted pilot programme.























