AI Pulse by Inblix

Google's Gemini 3.5 Flash Cyber found 10 zero-day-like bugs no other AI model could

The Verge AI · Jul 21, 2026 · 3 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Google's Gemini 3.5 Flash Cyber found 10 zero-day-like bugs no other AI model could

Google just drew a clear line in the sand for automated vulnerability hunting. On Tuesday, the company announced Gemini 3.5 Flash Cyber, a new security-specific model that’s built on the architecture of Gemini 3.5 Flash. The pitch is simple: it’s a cost-efficient workhorse designed to undercut pricey alternatives like Anthropic’s Mythos. Google is making the model available first to governments and trusted partners through CodeMender, its security-focused coding agent. The integration matters because CodeMender can invoke the model multiple times at high speed, letting it explore deep code paths that a more expensive, single-pass scan might miss.

And the results suggest that brute-forcing the problem with speed and low cost actually works. Google put 3.5 Flash Cyber up against much larger models on the CyberGym AI benchmark and called the performance “competitive” after multiple invocations. The real headline number, though, is in the V8 JavaScript Engine. The new model flagged 55 unique, confirmed security issues. That’s not just better than its base Gemini 3.5 Flash model, which found 47—it’s a significant jump over Claude Opus 4.6, which found 36. Crucially, Google says 10 of those 55 issues were found by no other model. It’s a strong signal that repeated, cheaper inference can surface vulnerabilities that single-pass analysis from a more “powerful” model leaves buried.

This launch is a direct shot at the pricing model for AI security. Anthropic’s Mythos 5, part of Project Glasswing, is a compute-hungry beast that costs twice as much as Opus 4.8. Microsoft’s adoption of Mythos led directly to its biggest Patch Tuesday ever this month, proving the value of AI in security but also exposing the immense cost. Google’s counter-argument is that you don’t necessarily need a massive, expensive model to get great results—you need a specialized one that’s cheap enough to run repeatedly. The broader Gemini update also includes an upgraded 3.6 Flash with better coding and multimodal chops, and a 3.5 Flash-Lite billed as the most cost-effective model in the series.

It’s a fascinating strategic turn. While Anthropic is betting on sheer model size and Microsoft is happy to pay the premium for it, Google is flooding the zone with speed and affordability. The fact that this model is initially locked to CodeMender and government partners also suggests Google is prioritizing high-stakes environments where finding that one extra vulnerability justifies the cost of the tool. Whether a cheaper model can consistently out-hunt a giant like Mythos on a broader set of targets remains an open question, but for now, the tally of unique bugs found in V8 is hard to ignore.

💡 Key Takeaways

  1. Gemini 3.5 Flash Cyber found 55 confirmed vulnerabilities in the V8 JavaScript Engine, surpassing both its base model and Anthropic's Claude Opus 4.6.
  2. The model's strength is not just single-pass accuracy, but the ability to be invoked cheaply multiple times to discover new code paths that larger models miss.
  3. Google is undercutting the pricing of Anthropic's Mythos by offering a specialized model that is cost-efficient enough for rapid, repeated scanning.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

← Back to all articles