Google Unveils Gemini 3.8 Flash Cyber for Automated Vulnerability Discovery and Patching
Google has launched Gemini 3.8 Flash Cyber, an AI model designed to autonomously find and fix software security flaws, available to vetted teams through the Fairwind Program.

Google has introduced Gemini 3.8 Flash Cyber, a specialized variant of its latest reasoning and coding model family, engineered to autonomously discover software vulnerabilities and generate patches. This release follows closely on the heels of Gemini 3.7 Flash, marking Google's third "Flash-tier" model launch in six weeks, with both new models sharing an underlying architecture but tuned for distinct deployment scenarios.
The general-purpose Gemini 3.8 Flash model is optimized for long-horizon software engineering and agentic workloads. It reportedly demonstrates significant performance gains over its predecessor, 3.7 Flash, while maintaining the same competitive pricing. On the DeepSWE v1.1 benchmark for complex engineering tasks, it is said to outperform larger frontier models at a substantially lower cost, achieving a 54.9% score on HLE-Verified, indicating robust multi-step reasoning capabilities across technical and professional domains. Google attributes these advancements to the model's enhanced ability to perform iterative tool calls and extra reasoning steps when tackling challenging problems.
Gemini 3.8 Flash Cyber, however, is specifically tailored for cybersecurity applications. Its availability is restricted to vetted security teams through Google's new Fairwind Program, a measure reflecting the sensitive nature of a tool designed to identify exploitable weaknesses. Google emphasizes that the model's development prioritized defensive patching from the outset, rather than focusing on exploitation capabilities.
In cybersecurity benchmarks, Gemini 3.8 Flash Cyber reportedly surpasses its predecessor, 3.5 Flash Cyber, and even larger frontier competitors on CyberGym, a standard industry benchmark for vulnerability discovery. Further internal testing across twenty programming languages, extending beyond the typical C/C++ focus of CyberGym, yielded a success rate exceeding 70%, a notable improvement over previous versions. On the CWE-Bench, an external benchmark for automated fixes, the model achieved a pass@1 score of 47.2%, closely rivaling a leading frontier model's performance while operating at a significantly reduced cost.
Google reports that Gemini 3.8 Flash Cyber is already being integrated into its own security practices. The Chrome Security team found that the model generated 2.6 times more accurate vulnerability patches compared to larger commercial rivals. Security firm Wiz observed a 7.5 to 9.7 percent higher recall on internal penetration-testing benchmarks, at a two to five times lower cost. In a notable instance, Google's Cloud Vulnerability Research team utilized the model to discover a critical foundational vulnerability in under two hours, a task that typically requires months of manual effort.
The introduction of Gemini 3.8 Flash Cyber signifies Google's strategic push to equip defenders with an automated advantage against adversaries. By combining advanced agentic reasoning with specialized cybersecurity training, Google aims to accelerate the identification and remediation of vulnerabilities. However, broader access to this powerful tool remains limited to trusted participants in the Fairwind Program for the time being, underscoring the company's cautious approach to deploying such capabilities.
This development aligns with a growing trend in the cybersecurity industry to leverage artificial intelligence for proactive defense. As AI models become more sophisticated, their application in finding and fixing vulnerabilities before they can be exploited is becoming increasingly crucial for maintaining robust security postures across software development lifecycles.