Google launches a cheaper alternative to large AI security models like Mythos
Google has launched an AI security model named Gemini 3.5 Flash Cyber, designed to quickly find and patch vulnerabilities. It is a cost-efficient alternative to larger, more expensive models like Anthropic's Mythos. The model is built on Gemini 3.5 Flash and will be available first to governments via CodeMender. Google claims it achieved competitive performance on cybersecurity benchmarks and identified 55 unique issues in the V8 engine.
Google is launching an AI security model dedicated to quickly finding and patching security vulnerabilities. In a blog post on Tuesday, Google describes Gemini 3.5 Flash Cyber as a “cost-efficient and highly capable alternative” to larger, more expensive AI systems, such as the one offered by Anthropic’s Mythos. The new model is built upon Gemini 3.5 Flash and will be available first to governments and trusted partners via CodeMender, Google’s security-focused coding agent. As noted by Google, CodeMender can call upon 3.5 Flash Cyber “multiple times at high speed and low cost,” allowing the AI agents to scan more code paths and find vulnerabilities. Anthropic’s Mythos 5 is a powerful AI security model released as part of the company’s Project Glasswing initiative. The compute-heavy model is expensive to use, costing twice as much as Claude Opus 4.8. Microsoft, which adopted Mythos for its security checks, had its biggest Patch Tuesday this month after using AI to find vulnerabilities. Other companies, like Google, are racing to keep up, while China’s Z.ai claims its model can compete with Mythos. Google says 3.5 Flash Cyber achieved “competitive performance” compared to “significantly larger models” on the CyberGym AI cybersecurity benchmark when called upon up to five times. It also identified 55 “unique confirmed issues” in the V8 JavaScript Engine, compared to 47 found by Gemini 3.5 Flash and 36 by Opus 4.6. Google adds that 3.5 Flash Cyber found 10 issues that no other model discovered, noting that the model continued to find new code paths and vulnerabilities after being invoked multiple times.