Cyber Security News

Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities

Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and generate working patches for them.

The release arrives just three weeks after Gemini 3.7 Flash, marking Google’s third Flash-tier launch in six weeks, and both new models share the same underlying architecture while being tuned for different deployment scenarios.

Google Launches Gemini 3.8 Flash Cyber

The general-purpose Gemini 3.8 Flash targets long-horizon software engineering and agentic workloads, offering meaningful gains over 3.7 Flash while keeping the same introductory pricing of $0.75 per million input tokens and $3.75 per million output tokens.

On the DeepSWE v1.1 benchmark for complex, end-to-end engineering tasks, it reportedly outperforms several larger frontier models at a fraction of the cost, and it scores 54.9% on HLE-Verified, reflecting strong multi-step reasoning across technical and professional domains.

Google attributes these gains to the model’s willingness to take extra reasoning steps and call tools iteratively when tackling difficult problems, though this can increase token usage at higher effort settings.

Gemini 3.8 Flash DeepSWE v1.1 Evaluation (Image Source: Google)

The cybersecurity-focused Gemini 3.8 Flash Cyber is being made available exclusively to vetted security teams through Google’s new Fairwind Program, as announced in Google’s research publication, reflecting the sensitivity of a model trained to find exploitable flaws.

On CyberGym, a widely used industry benchmark for vulnerability discovery, the model reportedly surpasses both its predecessor, 3.5 Flash Cyber, and significantly larger frontier competitors.

Google also tested the model against an internal benchmark spanning twenty programming languages beyond the C/C++ focus of CyberGym, where it achieved a success rate exceeding 70%, a notable jump over prior versions.

Model VariantPrimary Focus & Target WorkloadsKey Benchmark PerformanceAccess & Deployment Model
Gemini 3.8 FlashLong-horizon software engineering & agentic workflowsDeepSWE v1.1 frontier outperformance; 54.9% on HLE-VerifiedGeneral availability ($0.75 / $3.75 per 1M tokens)
Gemini 3.8 Flash CyberAutonomous vulnerability hunting & automated patching>70% across 20 languages; 47.2% CWE-Bench pass@1Vetted security teams via Google Fairwind Program

Rather than emphasizing exploitation capabilities, Google says it deliberately prioritized defensive patching from the outset.

On CWE-Bench, an external benchmark for automated fixes run by Collinear, Gemini 3.8 Flash Cyber posted a pass@1 score of 47.2%, nearly matching a leading frontier model’s 47.8% while running at a considerably lower cost.

Gemini 3.8 Flash Cyber CWE-Bench Pass@1 vs. Cost per Rollout (Image Source: Google)

Google states the model is already securing its own codebases. The Chrome Security team found it produced 2.6 times more correct vulnerability patches than larger commercial rivals, while security firm Wiz measured 7.5 to 9.7 percent higher recall on internal penetration-testing benchmarks at two to five times lower cost.

In one striking case, Google’s Cloud Vulnerability Research team used the model to uncover a critical foundational vulnerability in under two hours, a discovery process that typically takes months of manual research.

By pairing agentic reasoning with domain-specific cybersecurity training, Gemini 3.8 Flash Cyber signals Google’s push to give defenders an automated edge over attackers, even as broader access remains limited to trusted program participants for now.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

4 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

15 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

16 hours ago