Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting

Google Released Gemini 3.5 Flash Cyber AI, a Specialized AI Model for Vulnerability Hunting

Pierluigi Paganini
July 23, 2026

Google DeepMind unveiled Gemini 3.5 Flash Cyber, an AI model for vulnerability discovery and patching, available only to governments and trusted partners.

Google DeepMind announced Gemini 3.5 Flash Cyber on Tuesday, a security-focused AI model built on top of the existing 3.5 Flash architecture and designed specifically to find, validate, and patch software vulnerabilities. It won’t be available to the general public.

“Given the dual-use nature of this technology, we have taken an intentional approach to deploying 3.5 Flash Cyber. The model will be exclusively available to governments and trusted partners via CodeMender soon as part of a limited-access pilot program.” reads the announcement. “This will give frontline defenders a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse.”

The access restriction is deliberate and explicitly tied to the dual-use risk of a model this capable at offensive security work.

The model is designed to be fast and cheap to run, not just accurate.

“Flash’s performance and efficiency makes it an ideal foundation to detect, validate, and patch code security issues at scale.” continues the announcement. “Gemini 3.5 Flash Cyber is built on top of 3.5 Flash, and fine-tuned for finding and fixing cybersecurity vulnerabilities at a lower price per token than larger models.”

Because CodeMender runs multiple 3.5 Flash Cyber agents working in parallel to produce a single combined report, the cost-per-token advantage compounds into significantly more code coverage per session.

Within CodeMender’s multi-agent setup, 3.5 Flash Cyber reaches competitive performance at the frontier on the CyberGym benchmark, the standard evaluation for this class of capability.

Google’s announcement frames the product design in terms that reflect what’s actually changed in the threat landscape.

“AI models have become capable of finding security vulnerabilities faster than current systems can fix them. Tackling this growing threat requires an approach to securing software that is highly capable and efficient.” states Google.

That framing acknowledges something the industry has been circling around: the offensive capability of these models is now outpacing the speed at which defenders can respond to what they find.

The restricted deployment is designed to close that gap from the defensive side first. Governments and trusted partners get early access to the model, giving defenders a head start on finding and fixing critical vulnerabilities before they can be exploited. A DeepMind spokesperson confirmed plans to add red-teaming features and end-to-end enterprise defense capabilities over time.

3.5 Flash Cyber ships alongside two additional model releases. Gemini 3.6 Flash is the updated workhorse model, delivering better coding, knowledge work, and multimodal performance while consuming 17% fewer output tokens than 3.5 Flash according to the Artificial Analysis Index.

“Gemini 3.6 Flash builds directly on developer and customer feedback from 3.5 Flash. 3.6 Flash not only delivers a step up in coding and knowledge work, but it does this while meaningfully improving token efficiency.” states Google. “This enhanced efficiency is also combined with a lower price than 3.5 Flash. At $1.50/1M input tokens and $7.50/1M output tokens, 3.6 Flash reduces the overall cost per agentic task, making agents more cost-effective to build and run.”

It’s priced at $1.50 per million input tokens and $7.50 per million output tokens. On benchmarks like DeepSWE it shows up to 65% token reduction in some configurations, and it outperforms 3.5 Flash on software engineering (49% vs. 37% on DeepSWE), machine learning research (63.9% vs. 49.7% on MLE Bench), and computer use tasks (83.0% vs. 78.4% on OSWorld-Verified).

Gemini 3.5 Flash-Lite is built for speed and scale. It runs at 350 output tokens per second according to Artificial Analysis, priced at $0.30 per million input tokens and $2.50 per million output tokens.

“3.5 Flash-Lite is the fastest model in the 3.5 series. As measured by Artificial Analysis, it runs at 350 output tokens/s. Priced at $0.3/1M input tokens and $2.5/1M output tokens and with significantly better quality than 3.1 Flash-Lite, 3.5 Flash-Lite offers a strong price-to-performance ratio for developers and customers running high throughput production traffic.” continues the report.

It now also includes computer use as a built-in tool, and on several agentic benchmarks it outperforms the older 3 Flash model outright.

3.6 Flash and 3.5 Flash-Lite are available immediately through Google AI Studio, the Gemini API, the Gemini Enterprise Agent Platform, and the Gemini app. Google separately noted that Gemini 3.5 Pro is currently being tested with partners and will be made broadly available when ready, and that pre-training has already started on Gemini 4.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *