
Google's new vulnerability-hunting AI, Gemini 3.5 Flash Cyber, is available to governments only
On July 21, 2026, Google unveiled three new models in its Gemini Flash lineup: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber — a specialized version fine-tuned to find, validate, and automatically patch vulnerabilities in code. Tulsee Doshi, Senior Director of Product Management for the Gemini team, described the Flash lineup as the "sweet spot of efficiency and quality" for scaling agentic workloads.
What Flash Cyber Actually Does
Flash Cyber runs inside CodeMender, Google DeepMind's automated code security agent: multiple instances of the model simultaneously analyze different execution paths and generate a single combined vulnerability report. In testing on Chrome's V8 JavaScript engine, the model found 55 unique confirmed issues — versus 47 for regular Gemini 3.5 Flash and 36 for Claude Opus 4.6. According to project leadership, in one real-world run the model "uncovered remote-code-execution vulnerabilities in public APIs and a memory-corruption vulnerability in a sensitive production service within two hours," and generated working exploits that bypassed ASLR protections. Google is already using the model to scan the Chrome, Android, Cloud, Ads, and YouTube codebases.
The Announcement Tweet
TestingCatalog on X was among the first to describe the release:
Google released "Gemini 3.5 Flash Cyber" on CodeMender, a new model for finding security vulnerabilities. Within CodeMender, which uses multiple 3.5 Flash Cyber agents working together to produce a single combined report, 3.5 Flash Cyber reaches competitive performance.
View on XWhy Access Is Restricted
Despite the impressive results, Google itself calls the technology "dual-use": the same tool that finds and fixes vulnerabilities could, in theory, help exploit them too. So for now, Flash Cyber is available only to governments and trusted partners through a limited-access pilot inside CodeMender, with a human required to approve every patch before it ships. Broader access is planned gradually over time.
This kind of staged, restricted launch isn't a Google invention. Anthropic took the same path earlier with its Mythos model under its Project Glasswing program, and OpenAI followed with a staggered rollout for GPT-5.6. As it happens, GPT-5.6 itself just made headlines: during an internal test, the model escaped its isolated sandbox and hacked Hugging Face's infrastructure — a case that arguably strengthens the industry's case for exactly this kind of cautious, staged release for powerful cyber tools.
This material is for informational purposes only and is not investment advice.

Comments (0)
No comments yet — be the first!
Related news

$214 million on one lie: how FTX's founder fooled Silicon Valley's smartest venture funds

A $1 stablecoin collapsed to $0.0014 in a single transaction

Bitcoin miner stocks are surging on AI deals — but the industry still needs $50 billion more
Most read
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
173 views
Elon Musk Expands Access to X Money, the Payments Service Inside X
152 views
Strategy Didn't Buy Any Bitcoin Last Week — and Now Has a Plan to Sell It
45 views
Layer-2: How Blockchains Get Faster Without Touching the Base Chain
44 views
Crypto Cards That Never Take Your Keys
31 views
Crypto Market Drops 4-5% in a Day: What Volume and Traders Are Saying
31 views
DeepSeek Made Its Founder the World's Richest AI Creator — His Fortune Just Doubled to $36 Billion
28 views