
Google’s DeepMind announced on Tuesday the release of Gemini 3.5 Flash Cybera dedicated artificial intelligence (AI) model based on 3.5 Flash designed to quickly and efficiently detect, validate and remediate vulnerabilities.
According to the tech giant, the model will be available exclusively through CodeMender to governments and trusted partners as part of a limited access pilot program. CodeMender is an AI-powered vulnerability detection and patching agent introduced by the company in October 2025.
A Google DeepMind spokesperson told The Hacker News that there are plans to expand the model’s capabilities to include red teaming capabilities and end-to-end enterprise defense.
The lightweight model is both a cost-effective and high-performance alternative to large, expensive cybersecurity-focused models, according to DeepMind. CodeMender can invoke 3.5 Flash Cyber “multiple times at high speed and low cost,” allowing the AI agent to scan more code paths and find vulnerabilities.
The release of 3.5 Flash Cyber comes alongside Gemini 3.6 Flash and 3.5 Flash-Lite, which are optimized for improved coding, knowledge work and multi-modal performance and low latency tasks, respectively.
“Given the dual-use nature of this technology, we took a deliberate approach in deploying 3.5 Flash Cyber,” said Raluca Ada Popa, Gemini Security Lead at DeepMind, and Four Flynn, Vice President of Security and Privacy at DeepMind, in a blog post shared with The Hacker News ahead of publication.
“As part of a limited-access pilot program, 3.5 Flash Cyber will be available exclusively to governments and trusted partners through CodeMender and will be expanded over time. This will give frontline defenders a head start in finding and remediating critical vulnerabilities before they can be exploited, while preventing broader abuse.”
Because 3.5 Flash Cyber runs exclusively within CodeMender, it is easy to configure guardrails that specifically activate only the AI agent’s defensive functions and disable other cyber activities, the spokesperson added. This is intended to prevent scenarios where a model refuses to deal with scenarios that prohibit defenders from conducting AI-powered forensic analysis.

AI Research Lab evaluations found that 3.5 Flash Cyber Gemini outperforms 3.5 Flash and 3.6 Flash when it comes to uncovering new vulnerabilities in code bases. Additional stress testing of the model in complex projects such as Google Chrome and Apple Safari found that it “significantly” outperformed Gemini 3.5 Flash, 3.6 Flash and Anthropic Claude Opus 4.6.
“3.5 Flash Cyber has consistently discovered more unique vulnerabilities compared to 3.5 Flash and Claude Opus 4.6,” it says. “When tested with the highly complex V8 JavaScript engine over a set number of invocations, Gemini 3.5 Flash Cyber found 55 unique confirmed issues, compared to 47 from Gemini 3.5 Flash and 36 from Opus 4.6, including 10 issues that no other model detected.”
As was the case with Anthropic and OpenAI, Google 3.5 put Flash Cyber to the test to uncover remote code execution vulnerabilities in public APIs and a memory corruption vulnerability in a sensitive production service. The model is also said to have produced a 100% reliable remote code execution exploit that bypassed standard mitigation techniques such as Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X).
Google said it is making CodeMender’s core functionality separately directly available to customers with generally available Gemini models through the Gemini Enterprise Agent Platform.
“By equipping CodeMender with 3.5 Flash Cyber, we are providing a high-performance, scalable, and affordable architecture designed to help more defenders secure software,” it continued.
https://thehackernews.com/2026/07/google-launches-gemini-35-flash-cyber.html
