All news

Google Launches Gemini 3.5 Flash Cyber, a Vulnerability-Hunting Model That Outscores Claude Opus 4.6

Google DeepMind released a specialized cybersecurity variant of Gemini 3.5 Flash on July 21 that found more confirmed bugs in Chrome's V8 engine than both mainline Flash and Claude Opus 4.6, though access is currently limited to governments and select partners.


Google DeepMind released Gemini 3.5 Flash Cyber on July 21, a version of Gemini 3.5 Flash fine-tuned specifically to find, validate and patch software vulnerabilities. It plugs into Google's CodeMender security platform rather than shipping as a general chat or coding model.

  • Found 55 unique confirmed vulnerabilities in Chrome's V8 JavaScript engine, versus 47 for mainline Gemini 3.5 Flash and 36 for Claude Opus 4.6
  • 10 of those bugs were missed entirely by the competing models
  • Google's Cloud Vulnerability Research team used it to find remote-code-execution and memory-corruption flaws in production services within 2 hours

Google credits the model's low cost per call for the gain: it can be invoked many times over a codebase to widen coverage, where a larger model is usually run once. Access is currently restricted to a pilot for governments and trusted partners through CodeMender, with a broader rollout planned via the Gemini Enterprise Agent Platform. The release lands alongside this week's general-purpose Gemini 3.6 Flash and 3.5 Flash-Lite, while the flagship Gemini 3.5 Pro remains delayed. You can compare Gemini and Claude on real coding tasks in our coding arena.

More AI news in Polish at nowosci.ai