Google announced in July 2026 the release of Gemini 3.5 Flash Cyber, a cybersecurity-focused AI model designed to find and patch security vulnerabilities at lower cost than larger competing systems, including Anthropic’s Mythos.
Described by Google in a blog post as a “cost-efficient and highly capable alternative” to more expensive AI models, Gemini 3.5 Flash Cyber is built on the Gemini 3.5 Flash foundation. It will initially be available to governments and trusted partners through CodeMender, Google’s security-focused coding agent. Google says CodeMender can call upon the model “multiple times at high speed and low cost,” enabling AI agents to scan more code paths and identify vulnerabilities more thoroughly.
On the CyberGym AI cybersecurity benchmark, Google reports that 3.5 Flash Cyber achieved “competitive performance” compared to “significantly larger models” when invoked up to five times. In testing against the V8 JavaScript Engine, the model identified 55 unique confirmed issues — compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6. Google also notes that 3.5 Flash Cyber found 10 issues that no other model discovered, and continued to surface new vulnerabilities with repeated invocations.
Alongside the cybersecurity model, Google announced Gemini 3.6 Flash, an upgraded general-purpose model with improvements in coding and multimodal performance, and Gemini 3.5 Flash-Lite, described as the “most cost-effective” model in the 3.5 series.
The launch positions Google’s smaller, specialized model as a direct alternative to larger and costlier AI security systems. The ability to run the model repeatedly at low cost may allow organizations to conduct broader vulnerability scans than would be practical with more expensive options.
Source: The Verge