Google has been a pioneer in automated vulnerability discovery to secure the world’s codebases. Today, they introduced Gemini 3.5 Flash Cyber, a lightweight cybersecurity model built on 3.5 Flash, designed to quickly and efficiently find, validate, and patch vulnerabilities, outperforming the mainline Flash models.
Gemini 3.5 Flash Cyber is particularly suitable for scanning large codebases and analyzing numerous code paths. By invoking 3.5 Flash Cyber multiple times via CodeMender, agents can analyze significantly more code paths, producing a high-quality report. Its speed and cost-effectiveness make it ideal for frequent scans and time-sensitive launch processes.
In benchmarks like CyberGym, 3.5 Flash Cyber achieved competitive performance against larger models. It also excelled in Google Chrome’s production commit scanning pipeline, discovering more unique vulnerabilities than the mainline 3.5 Flash model.
3.5 Flash Cyber is already finding and fixing vulnerabilities in Google’s internal codebases, including Chrome and Android. The Cloud Vulnerability Research team utilized the model to uncover multiple remote code execution vulnerabilities in just two hours, showcasing significant capability improvements.
With the support of OSV.dev and OSS-Fuzz results, Google can identify high-quality vulnerabilities, enhancing the model’s effectiveness. The launch of 3.5 Flash Cyber provides defenders with powerful tools and lays a solid foundation for the future of cybersecurity.
Blogger's Review: The introduction of the Gemini 3.5 Flash Cyber model signifies a major breakthrough in Google's cybersecurity technology, particularly its efficiency and affordability, empowering defenders with robust tools. The challenge will be to balance technological capabilities with security risks as the industry advances.