Aakib Ansari.
Back to articles
News Brief

Google Built a Vulnerability-Hunting AI and Locked It Behind a Government-Only Pilot

Md Aakib Ansari
Md Aakib AnsariWeb Developer & AI Tools Reviewer
Updated 3 min readModel: Gemini 3.5 Flash Cyber
Google Built a Vulnerability-Hunting AI and Locked It Behind a Government-Only Pilot

Google DeepMind released Gemini 3.5 Flash Cyber on July 21, a specialized security model built on top of Gemini 3.5 Flash and fine-tuned to find, validate, and patch software vulnerabilities — and unlike the two other models announced the same day, it isn't going to the public.

Access is limited to governments and trusted partners through Google's CodeMender program, as part of what the company calls a limited-access pilot with no public API, no published pricing, and no self-serve signup. Google says the model has already been running internally across Chrome, Android, Cloud, Ads, and YouTube codebases, and cites a benchmark where it found 55 confirmed issues in V8 JavaScript engine testing against 36 for Claude Opus — though that comparison relies on Google's own unpublished vulnerability set rather than an independently reproducible test.

Google frames the restriction as intentional rather than a rollout delay. In DeepMind's announcement, security lead Raluca Ada Popa and VP Four Flynn described the approach as tied directly to the model's dual-use risk: a system this effective at discovering exploitable bugs is equally useful to whoever gets to run it, so the company is controlling distribution from launch rather than relying on usage guardrails after the fact.

The move puts Flash Cyber in the same emerging category as Anthropic's approval-gated Mythos models — frontier-adjacent capability that labs are choosing to build but not ship broadly. It's a notable shift from Google's usual API-first playbook, and one of the clearer signals yet that offensive-security capability is now advancing fast enough that even its developers don't trust open distribution.

Related Articles

Meta Releases Muse Glimmer: Apache 2.0 Licensed 30B Local Agent Model
News Brief2 min read
Meta Releases Muse Glimmer: Apache 2.0 Licensed 30B Local Agent Model

Meta Superintelligence Labs has released Muse Glimmer, a 30-billion parameter open-weight model distilled from its proprietary Muse Spark flagship. Published under an Apache 2.0 license, Glimmer is purpose-built for offline, on-device agentic workloads like coding, debugging, and file management on consumer hardware.

Ant Group's inclusionAI Team Releases Ling 3.0 Flash FP8 Under MIT License
News Brief2 min read
Ant Group's inclusionAI Team Releases Ling 3.0 Flash FP8 Under MIT License

Ant Group's inclusionAI team has released Ling 3.0 Flash FP8, a highly efficient 124-billion parameter Mixture-of-Experts (MoE) model. Featuring an MIT license and a custom hybrid attention architecture, the model reduces active parameters to 5.1 billion per token, matching the performance of much larger models while dramatically lowering operational costs.

Liquid AI's LFM2.5-2.6B Matches Models Three Times Its Size on Agentic Tasks
News Brief2 min read
Liquid AI's LFM2.5-2.6B Matches Models Three Times Its Size on Agentic Tasks

Liquid AI released LFM2.5-2.6B on August 4, a 2.69B-parameter on-device model purpose-built for agentic workloads. Using a hybrid architecture of short convolution blocks and grouped query attention, it runs under 2.5 GB of memory and reaches approximately 220 tokens/s on Apple M5 Max — while matching or exceeding Qwen3.5-9B on tool use and instruction-following benchmarks.