Gemini 3.5 Flash Cyber Finds 55 V8 Bugs as Access Stays Limited
Original: Gemini 3.5 Flash Cyber Finds 55 V8 Issues Under Limited Access View original →
A smaller cyber model built for repeated scans
The shift is not just another larger model. Google DeepMind is testing whether a lighter, specialized model can search more code paths at lower cost. In its July 23 X post, the lab described Gemini 3.5 Flash Cyber as a model to help “spot and patch vulnerabilities” before exploitation.
“spot and patch vulnerabilities” — Google DeepMind
The linked DeepMind post says Gemini 3.5 Flash Cyber is built on top of 3.5 Flash and tuned for finding, validating, and patching software flaws. It runs through CodeMender, Google’s code-security agent, where multiple calls can examine different paths and combine the result into one report. Access is not public: DeepMind says the model will first be available to governments and trusted partners through a limited pilot.
The benchmark signal
The strongest evidence is the V8 JavaScript Engine test. Under a fixed number of invocations, Flash Cyber found 55 unique confirmed issues. Mainline Gemini 3.5 Flash found 47, while Claude Opus 4.6 found 36; 10 of the Flash Cyber findings were missed by both comparison models. DeepMind also points to CyberGym, Big Sleep evaluations, and Chrome production commit scanning as evidence that the tuned model works better than general Flash variants on security tasks.
Google DeepMind’s X account often uses short posts as pointers to deeper research or product write-ups, and this one fits that pattern. The tweet is the public signal; the linked blog supplies the deployment policy and evaluation details. The next thing to watch is whether CodeMender’s limited pilot expands beyond government and trusted-partner access, and whether Google can keep defensive workflows usable while constraining dual-use cyber capabilities.
Related Articles
Google is steering Gemini toward cost-controlled production agents rather than a single flagship race. The new 3.6 Flash cuts output token use by 17% versus 3.5 Flash, while 3.5 Flash-Lite reaches 350 output tokens per second.
Google’s Gemini Flash update is less about another model name and more about the economics of long-running agent workflows: fewer output tokens, lower prices, and a cyber-specialized variant tied to CodeMender.
Agent competition is moving from answer quality to controlled action on screens. Google DeepMind says Gemini 3.5 Flash now has a built-in computer-use tool for browser, mobile, and desktop interfaces.