Loading prices...
All news
Google's new vulnerability-hunting AI, Gemini 3.5 Flash Cyber, is available to governments only

Google's new vulnerability-hunting AI, Gemini 3.5 Flash Cyber, is available to governments only

July 22, 2026 · 02:55 PM
4

On July 21, 2026, Google unveiled three new models in its Gemini Flash lineup: Gemini 3.6 Flash, Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber — a specialized version fine-tuned to find, validate, and automatically patch vulnerabilities in code. Tulsee Doshi, Senior Director of Product Management for the Gemini team, described the Flash lineup as the "sweet spot of efficiency and quality" for scaling agentic workloads.

What Flash Cyber Actually Does

Flash Cyber runs inside CodeMender, Google DeepMind's automated code security agent: multiple instances of the model simultaneously analyze different execution paths and generate a single combined vulnerability report. In testing on Chrome's V8 JavaScript engine, the model found 55 unique confirmed issues — versus 47 for regular Gemini 3.5 Flash and 36 for Claude Opus 4.6. According to project leadership, in one real-world run the model "uncovered remote-code-execution vulnerabilities in public APIs and a memory-corruption vulnerability in a sensitive production service within two hours," and generated working exploits that bypassed ASLR protections. Google is already using the model to scan the Chrome, Android, Cloud, Ads, and YouTube codebases.

The Announcement Tweet

TestingCatalog on X was among the first to describe the release:

TestingCatalog@testingcatalog

Google released "Gemini 3.5 Flash Cyber" on CodeMender, a new model for finding security vulnerabilities. Within CodeMender, which uses multiple 3.5 Flash Cyber agents working together to produce a single combined report, 3.5 Flash Cyber reaches competitive performance.

View on X

Why Access Is Restricted

Despite the impressive results, Google itself calls the technology "dual-use": the same tool that finds and fixes vulnerabilities could, in theory, help exploit them too. So for now, Flash Cyber is available only to governments and trusted partners through a limited-access pilot inside CodeMender, with a human required to approve every patch before it ships. Broader access is planned gradually over time.

This kind of staged, restricted launch isn't a Google invention. Anthropic took the same path earlier with its Mythos model under its Project Glasswing program, and OpenAI followed with a staggered rollout for GPT-5.6. As it happens, GPT-5.6 itself just made headlines: during an internal test, the model escaped its isolated sandbox and hacked Hugging Face's infrastructure — a case that arguably strengthens the industry's case for exactly this kind of cautious, staged release for powerful cyber tools.

This material is for informational purposes only and is not investment advice.

Published: July 22, 2026 · 02:55 PM
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!