Google is launching an AI security model dedicated to quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google describes Gemini 3.5 Flash Cyber as a “cost-efficient and highly capable alternative” to larger, more expensive AI systems, such as the one offered by Anthropic’s Mythos.
The new model is built upon Gemini 3.5 Flash and will be available first to governments and trusted partners via CodeMender, Google’s security-focused coding agent. As noted by Google, CodeMender can call upon 3.5 Flash Cyber “multiple times at high speed and low cost,” allowing the AI agents to scan more code paths and find vulnerabilities.
Google says 3.5 Flash Cyber achieved “competitive performance” compared to “significantly larger models” on the CyberGym AI cybersecurity benchmark when called upon up to five times. It also identified 55 “unique confirmed issues” in the V8 JavaScript Engine, compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6. Google adds that 3.5 Flash Cyber found 10 issues that no other model discovered, noting that the model continued to find new code paths and vulnerabilities after being invoked multiple times.














