"Given the dual-use nature of this technology, we have taken an intentional approach to how we deploy 3.5 Flash Cyber," Raluca Ada Popa, DeepMind's Gemini Security Lead, and Four Flynn, vice president of security and privacy at DeepMind, wrote in a blog post shared with The Hacker News ahead of publication.
Gemini 3.5 Flash Cyber: a lightweight model built for fast vulnerability work
DeepMind announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence model built atop 3.5 Flash and designed to discover, validate, and patch vulnerabilities quickly and efficiently. According to the company, the model is a "lightweight" option that offers a cost-efficient and highly capable alternative to larger, more costly cybersecurity-focused models. DeepMind said CodeMender, its AI-powered agent for vulnerability discovery and patching, can call upon 3.5 Flash Cyber "multiple times at high speed and low cost," enabling the agent to scan more code paths and find more vulnerabilities.
CodeMender pilot: limited access for governments and trusted partners
DeepMind said 3.5 Flash Cyber will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access pilot program. CodeMender itself was unveiled by the company in October 2025. The company framed the pilot as a way to give "frontline defenders a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse," and stated the program will expand over time.
Comparative evaluations: V8 JavaScript Engine, Chrome, and Safari
The AI research laboratory reported that 3.5 Flash Cyber outperformed both Gemini 3.5 Flash and Gemini 3.6 Flash when it came to unearthing new vulnerabilities in codebases. In stress-testing on complex projects including Google Chrome and Apple Safari, DeepMind said 3.5 Flash Cyber "significantly" surpassed Gemini 3.5 Flash, 3.6 Flash, and Anthropic Claude Opus 4.6. When tested on the highly complex V8 JavaScript Engine across a fixed number of invocations, Gemini 3.5 Flash Cyber reportedly found 55 unique confirmed issues, compared to 47 found by Gemini 3.5 Flash and 36 found by Opus 4.6 — including 10 issues that no other model caught.
Security testing outcomes: remote code execution and mitigation bypasses
DeepMind said it has used 3.5 Flash Cyber to test for remote code execution vulnerabilities in public APIs and to probe a memory-corruption vulnerability in a sensitive production service. The company asserted the model produced a 100% reliable remote-code execution exploit that bypassed standard mitigation techniques, specifically naming Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X).
How governments, customers, and adversaries are positioned
- Governments and trusted partners: As exclusive pilot participants, they will have early access to CodeMender powered by 3.5 Flash Cyber; DeepMind says that access is intended to give "frontline defenders a head start" in finding and fixing critical flaws.
- Customers and enterprises: Google said it is separately bringing CodeMender's foundational capabilities directly to customers through generally available Gemini models on the Gemini Enterprise Agent Platform, signaling that some features will become more broadly accessible beyond the pilot.
- Adversaries and threat actors: DeepMind acknowledged the tool's "dual-use nature" and framed the limited-access pilot and staged rollout as measures to mitigate against broader misuse.
Expansion through the Gemini Enterprise Agent Platform
DeepMind released 3.5 Flash Cyber alongside Gemini 3.6 Flash and 3.5 Flash-Lite, the latter two described as optimized for improved coding, knowledge work, multimodal performance, and low-latency tasks. While 3.5 Flash Cyber will be restricted initially to CodeMender pilot partners, the company also said it will bring CodeMender's foundational capabilities directly to customers using generally available Gemini models through the Gemini Enterprise Agent Platform. That dual path — a limited pilot for the specialized cyber model and a broader customer rollout of core CodeMender features — frames the company's stated approach to balancing capability, cost, and control.
DeepMind's claims present a concrete trade-off: a tool that the company says can find previously unseen issues and even generate highly reliable exploits, paired with a staged access plan intended to limit misuse while extending defensive benefits. How quickly the pilot expands, which partners are admitted, and how those capabilities are reflected in the Gemini Enterprise Agent Platform are the immediate, stated next steps the company has identified.
Source: The Hacker News — Google Launches Gemini 3.5 Flash Cyber




