Google Launches Gemini 3.8 Flash Cyber for Autonomous Vulnerability Detection and Remediation
Google announced Gemini 3.8 Flash Cyber, a specialized AI model optimized for autonomous vulnerability discovery and defensive patch generation. The model is already fully deployed across Google's internal security operations and released to trusted security teams via Google's Fairwind Program. By focusing on defensive remediation and achieving near-frontier performance at a significantly lower operational cost, Gemini 3.8 Flash Cyber gives defenders a major advantage against cyber threats. It enables security teams to reduce the time needed to identify and patch complex architectural vulnerabilities from months to mere hours. On the CWE-Bench benchmark, Gemini 3.8 Flash Cyber achieved a 47.2% Pass@1 accuracy, matching top-tier models while sitting on the Pareto Frontier of performance versus cost. In practical deployment, Chrome's security team found the model generated 2.6 times more valid patches than substantially larger commercial models.
## BACKGROUND
Defensive cybersecurity relies on identifying software vulnerabilities and applying patches before malicious actors can exploit them. Benchmarks like CWE-Bench and CyberGym are designed to evaluate how effectively AI agents audit code repositories and fix Common Weakness Enumerations (CWEs). Google's Fairwind Program provides enterprise and government partners with access to high-capability AI security tools built specifically for defensive use cases.