Google and Google DeepMind introduced Gemini 3.5 Flash Cyber, a security-focused AI model designed to find, validate, and help remediate software vulnerabilities. Built on Gemini 3.5 Flash, the model is positioned for defensive cybersecurity use cases including bug discovery, exploit analysis, and patch generation, and is being offered through CodeMender in a limited-access pilot for governments and other trusted partners because of its dual-use risk.
Google said internal testing showed the model outperforming Gemini 3.5 Flash, Gemini 3.6 Flash, and Anthropic Claude Opus 4.6 at identifying unique vulnerabilities, including in complex targets such as Google Chrome, Apple Safari, and the V8 JavaScript Engine. The company said the model uncovered remote code execution flaws, found a memory-corruption issue in a sensitive production service, and produced a reliable RCE exploit that bypassed ASLR and W^X mitigations; Google also said CodeMender’s core capabilities will be made available to customers through the Gemini Enterprise Agent Platform using generally available Gemini models.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Google stated that CodeMender’s foundational capabilities would be made available to customers through the Gemini Enterprise Agent Platform using generally available Gemini models. This marked the planned productization path for the security tooling beyond the restricted pilot.
Google said internal evaluations showed Gemini 3.5 Flash Cyber outperforming Gemini 3.5 Flash, Gemini 3.6 Flash, and Anthropic Claude Opus 4.6 at finding unique vulnerabilities. It also disclosed that the model identified remote code execution flaws, a memory-corruption issue in a sensitive production service, and generated a reliable RCE exploit that bypassed ASLR and W^X mitigations.
Google DeepMind announced Gemini 3.5 Flash Cyber, a specialized AI model for vulnerability discovery, validation, and patching. The company said the model would be offered through CodeMender in a limited-access pilot restricted to governments and trusted partners because of its dual-use potential.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcesecurityaffairs.com
Open sourcedeepmind.google
Open sourcethehackernews.com
Open sourceblog.google
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.