Google launches Gemini 3.5 Flash Cyber – a new AI security model to rival Anthropic's Mythos
"It's more efficient, and in some tests it performs competitively with much larger models."

Image by Google DeepMind
- Google launched Gemini 3.5 Flash Cyber, its first AI model fine-tuned to detect, validate, and patch software vulnerabilities.
- The lightweight model aims to deliver frontier-level cyber performance while lowering the cost of securing large codebases.
- Google's launch puts another major AI developer into the race to build specialized cybersecurity models for defenders.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Google DeepMind enters the AI cybersecurity race with Gemini 3.5 Flash Cyber, a lightweight security model designed to find, validate, and patch software vulnerabilities – and it's way cheaper than its much larger rivals Mythos and OpenAI’s Daybreak.
“Finding security vulns is only part of the battle: fixing them takes time & resources,” posted Heather Adkins, Vice President of Security at Google, also congratulating the Google DeepMind team on the release.
Google also debuted two upgraded Flash models on Tuesday: Gemini 3.6 Flash – a faster, cheaper, and smaller model for coding, as well as 3.5 Flash-Lite, now ranked as the fastest model in the Gemini series, delivering 350 output tokens per second.
Google says the “cost-efficient and highly capable” model was built on top of Gemini 3.5 Flash and developed to power its AI-driven CodeMender tool launched last October.
CodeMender – which now will use 3.5 Flash Cyber to scan code, build exploits, and generate patches – was integrated into the broader Gemini Enterprise Agent Platform in May.
"As AI agents become more capable at finding vulnerabilities faster than defenders can fix them, addressing this global threat requires a highly capable, affordable, and scalable approach,”Google’s DeepMind states.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Benchmarks pit 3.5 Flash Cyber against bigger rivals
According to Tuesday’s announcement on the DeepMind website, the dual-use system combines strong cyber capabilities with lower operating costs, allowing organizations to deploy multiple AI agents simultaneously to scan large codebases and investigate vulnerabilities.
What’s more, Google says its benchmark testing found 3.5 Flash Cyber performs competitively with significantly larger AI systems despite its smaller size – and in some cases, it found flaws its competitors had overlooked.
Google says 3.5 Flash Cyber is particularly suitable for finding vulnerabilities where the agent has to scan a large codebase and analyze a large number of code paths.
Putting its capabilities to the test on a variety of benchmarks using CyberGym – which evaluates AI agents against hundreds of real-world software vulnerabilities – Google says the model’s speed of discovery can deliver measurable impact.
“CodeMender invokes 3.5 Flash Cyber multiple times, so agents can analyze vastly more code paths to discover and validate vulnerabilities. The sub-agents then produce a single, high-quality report,”Google said.
In one test against the V8 JavaScript engine, the 3.5 Flash Cyber model identified 55 confirmed vulnerabilities, compared with 47 found by the more general Gemini 3.5 Flash.
Not only that, 3.5 Flash Cyber discovered 19 more vulnerabilities than the 36 found by Claude Opus 4.6 during testing.
Google also said the model uncovered 10 vulnerabilities neither system detected.
The company additionally says the cyber model outperformed its standard Gemini Flash models on Chrome commit analysis and Big Sleep evaluations, while remaining significantly cheaper to operate.
Broader rollout will be delayed
Google said 3.5 Flash Cyber will be made available through its CodeMender AI security agent for governments, trusted testers, and select security researchers before a broader rollout.
The delayed release echoes the initial rollout of Anthropic’s powerful Mythos and public-facing Fable models over national security concerns.
"This will give frontline defenders a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse,”Google said.
Separately, Google said it was also making CodeMender's foundational capabilities available to the public through its preview Gemini Enterprise Agent Platform.
Has your password leaked?