Google Debuts Gemini 3.5 Flash Cyber to Automate Vulnerability Patching

AI-generated image · Bay Street Wire
The new low-cost security model integrates with CodeMender to challenge compute-heavy alternatives like Anthropic's Mythos 5.
Google has launched Gemini 3.5 Flash Cyber, a specialized security model designed to identify and patch software vulnerabilities with high speed and lower costs. According to reporting from The Verge, the model is positioned as a cost-efficient alternative to larger, more expensive systems such as Anthropic's Mythos 5, which was released under the Project Glasswing initiative.
Google will first make the model available to trusted partners and governments through CodeMender, its security-focused coding agent. Because the model is lightweight, CodeMender can invoke Gemini 3.5 Flash Cyber multiple times rapidly, enabling the agent to scan a broader range of code paths. In testing on the CyberGym AI cybersecurity benchmark, Google reports that the model achieved competitive performance against significantly larger models when called up to five times. Specifically, the model identified 55 unique confirmed issues in the V8 JavaScript Engine, including 10 that no other model found. For comparison, Gemini 3.5 Flash found 47 issues and Opus 4.6 found 36, per The Verge.
This move comes as competitors scale their security AI. The Verge notes that Microsoft adopted Mythos 5 for its security checks, and China's Z.ai claims its own model can compete with Mythos. Additionally, Google introduced Gemini 3.6 Flash, which features multimodal and coding improvements, and Gemini 3.5 Flash-Lite, described as the most cost-effective model in the 3.5 series.

