Key takeaways

  • Google has invested in cybersecurity for years, pioneering automated vulnerability discovery to secure the world’s codebases.
  • 5 Flash Cyber will be exclusively available to governments and trusted partners via CodeMender soon, expanding over time.
  • Finding deep-seated flaws requires exploring an immense execution search space.

What happened

Google has invested in cybersecurity for years, pioneering automated vulnerability discovery to secure the world’s codebases. Tools like CodeMender, our code security agent, can automatically find and fix critical software vulnerabilities. But as AI agents become more capable at finding vulnerabilities faster than defenders can fix them, addressing this global threat requires a highly capable, affordable, and scalable approach.

The sub-agents then produce a single, high-quality report. 5 Flash Cyber can be easily integrated into frequent scans, time-sensitive launch processes or commit scanning pipelines at scale. 5 Flash Cyber on a variety of benchmarks. 5 Flash Cyber on the CyberGym benchmark, which evaluates AI agents against hundreds of real-world software vulnerabilities.

Why it matters

5 Flash and fine-tuned to find, validate, and patch vulnerabilities quickly and efficient, making it more effective at these tasks than Gemini’s mainline Flash models. Flash’s performance and efficiency makes it an ideal foundation for our cybersecurity model efforts. 5 Flash Cyber offers a cost-efficient and highly capable alternative to large, costly cybersecurity models. 5 Flash Cyber.

5 Flash Cyber will be exclusively available to governments and trusted partners via CodeMender soon, expanding over time. This will give frontline defenders a head start in finding and fixing critical vulnerabilities before they can be exploited, while mitigating against broader misuse. Separately, we're also bringing CodeMender's foundational capabilities directly to customers with generally available Gemini models through the Gemini Enterprise Agent Platform.

Finding deep-seated flaws requires exploring an immense execution search space. Relying on a single, expensive call to a massive language model can create a bottleneck. 5 Flash Cyber is particularly suitable for finding vulnerabilities where the agent has to scan a large codebase and analyze a large number of codepaths. 5 Flash Cyber multiple times, so agents can analyze vastly more code paths to discover and validate vulnerabilities.

What to watch

5 Flash Cyber up to five times for a single, final report, the overall agent achieved competitive performance against significantly larger models on CyberGym*. We also stress-tested the model’s capabilities beyond CyberGym without safety guardrails. Google’s Big Sleep team independently built an evaluation focused on finding critical and hard to find vulnerabilities in some of the world’s most complex codebases like Chrome and Safari. 6 Flash.

5 Flash Cyber was also evaluated on Google Chrome’s production commit scanning pipeline. The vulnerabilities were not publicly disclosed, which ensured this benchmark remained free of contamination for Gemini and competitor models. 5 Flash. 6 refuse to fulfill the tasks due to built-in safety guardrails, and therefore are not shown. 6. 6, including 10 issues that the other two models tested did