Will it run?
Security

Google DeepMind launches Gemini 3.8 Flash Cyber for vulnerability detection and autonomous patching

By Ilse Brandt Clawpit staff

Google DeepMind has unveiled a new model, Gemini 3.8 Flash Cyber, designed to find security vulnerabilities and generate fixes autonomously. According to the company, the model leads the CyberGym benchmark in autonomous vulnerability identification while maintaining speed and efficiency. The promise is that a "Flash"-sized model — a lighter, faster variant of the Gemini family — can handle complex code-repair tasks that typically require far larger and more expensive models.

The more compelling data point comes from an internal test on the Chrome codebase. Researchers say the model produced 2.6 times more valid fixes than the baseline, enabling security teams to protect software faster. The test ran in the organization's cloud environment, and the model delivered deployable fixes within minutes. It is important to note that the figure comes from Google itself, not an independent party, and no details were provided on sample size or the types of vulnerabilities tested.

Distribution is being handled through a program called Fairwind, which begins with limited access for national cyber authorities and essential service providers — telecommunications and energy networks — with the aim of protecting critical public infrastructure. At this stage there is no information on broader availability, a pricing model, or a target date for general release. The staged rollout suggests Google treats the model as a sensitive tool requiring tight controls before wider release.

The problem Google identifies is real: frontier-scale models are expensive and slow for day-to-day use, while smaller alternatives struggle with complex code repair. Gemini 3.8 Flash Cyber attempts to sit in the middle — fast enough for daily use, strong enough for real fixes. If the numbers hold up in external testing, it could change how SecOps teams handle zero-day vulnerabilities and routine security patches, but until independent results are published it remains a vendor claim.