
Google has introduced Gemini 3.5 Flash Cyber, a cost-efficient AI security model positioned as a cheaper alternative to Anthropic's expensive Mythos system, which costs twice as much as Claude Opus 4.8. The new model will initially be available to governments and trusted partners through CodeMender, Google's security-focused coding agent, and can be called upon multiple times at low cost to scan code and identify vulnerabilities. In benchmark testing, it achieved competitive performance against much larger models and found 55 confirmed vulnerabilities in the V8 JavaScript Engine—including 10 that no other model discovered.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Google released Gemini 3.5 Flash Cyber, a new AI security model built on Gemini 3.5 Flash, designed to find and patch software vulnerabilities quickly and affordably. The model will first be available to governments and trusted partners through CodeMender, Google's security-focused coding agent. Google also launched Gemini 3.6 Flash with improvements in coding and multimodal performance, and introduced 3.5 Flash-Lite as a more cost-effective option in the 3.5 series.
Why it matters
Anthropic's Mythos 5, a powerful but expensive security model (costing twice as much as Claude Opus 4.8), has set a high bar for AI-driven vulnerability detection—Microsoft adopted it for security checks and achieved its largest Patch Tuesday this month after using AI to find vulnerabilities. Google's new model offers competitive performance at a fraction of the cost, allowing CodeMender to scan code "multiple times at high speed and low cost," which means more thorough vulnerability detection for organizations that cannot afford premium alternatives.
What to watch
On the CyberGym AI cybersecurity benchmark, 3.5 Flash Cyber achieved competitive performance against significantly larger models when invoked up to five times. In real-world testing on the V8 JavaScript Engine, it identified 55 unique confirmed issues, compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6—and notably discovered 10 issues that no other model found.
Google announced the launch of Gemini 3.5 Flash Cyber on Tuesday, positioning it as a cost-efficient alternative to larger, more expensive AI systems such as Anthropic's Mythos. The new security model, built upon Gemini 3.5 Flash, is designed to quickly identify and patch software vulnerabilities and will be available first to governments and trusted partners through CodeMender, Google's security-focused coding agent.
Anthropics's Mythos 5, released as part of Project Glasswing, has become the market benchmark for AI-powered security scanning, but at a steep cost: it is compute-heavy and expensive to use, costing twice as much as Claude Opus 4.8. The high performance of Mythos has driven adoption; Microsoft, for example, adopted the model for its security checks and achieved its biggest Patch Tuesday this month after using AI to find vulnerabilities. Google's 3.5 Flash Cyber addresses the cost barrier by enabling CodeMender to call upon it "multiple times at high speed and low cost," allowing AI agents to scan more code paths and identify more vulnerabilities without breaking the budget.
Google's testing data supports the model's effectiveness despite its lower cost. On the CyberGym AI cybersecurity benchmark, 3.5 Flash Cyber achieved "competitive performance" compared to "significantly larger models" when invoked up to five times. More impressively, when tested on the V8 JavaScript Engine, the model identified 55 unique confirmed issues—more than Gemini 3.5 Flash (47 issues) and Opus 4.6 (36 issues). Notably, 3.5 Flash Cyber found 10 issues that no other model discovered, demonstrating that multiple invocations can surface new code paths and vulnerabilities that a single pass might miss.
Alongside 3.5 Flash Cyber, Google also released Gemini 3.6 Flash with improvements in coding and multimodal performance, and introduced 3.5 Flash-Lite as the "most cost-effective" model in the 3.5 series. These releases underscore Google's strategic shift toward balancing performance with affordability as competitive pressure in AI security and coding mounts, with other players such as China's Z.ai also claiming to compete with Mythos.
The launch of Gemini 3.5 Flash Cyber reflects intensifying competition in AI-powered security, particularly as Anthropic's Mythos 5 has raised the bar for vulnerability detection but at a prohibitively high cost. Mythos's adoption by Microsoft—and the resulting large volume of patched vulnerabilities in this month's Patch Tuesday—has made it clear that AI-driven security scanning can deliver real value, but only if the computational cost does not limit how frequently organizations can run it. Google's strategy targets this pain point directly: by making a smaller, cheaper model that CodeMender can invoke "multiple times at high speed and low cost," Google removes the economic barrier to repeated scanning.
The performance metrics Google cites show that the new model is genuinely competitive despite its lower cost. On the CyberGym benchmark, it matched larger models when called five times; on the V8 JavaScript Engine test, it found more vulnerabilities than both Gemini 3.5 Flash (55 vs. 47) and Claude Opus 4.6 (55 vs. 36), and crucially discovered 10 issues no other model found. This suggests that repeated invocations—enabled by low cost—may be more valuable than raw size, a finding that challenges the assumption that "bigger always means better" in security AI.
Google's broader model releases (Gemini 3.6 Flash and 3.5 Flash-Lite) fit into the same narrative: an emphasis on efficiency and cost-effectiveness across the product line. As China's Z.ai claims to offer competition to Mythos as well, the market for high-performance security AI is diversifying, and price-to-performance is becoming a key differentiator.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime
1 minute a day. The AI essentials.
200+ sources · Email / LINE / Slack