On September 2, 2026, Google DeepMind unveiled Gemini 3.8 Flash alongside a security-focused variant called Gemini 3.8 Flash Cyber, which the company says can autonomously detect software vulnerabilities and generate patches for them. In its own blog, Google positions the new Flash model as its “most intelligent workhorse,” citing marked gains in software engineering and multi-step reasoning.
What Gemini 3.8 Flash offers
According to Google, the model takes text, image, audio, video and PDF input, offers a one-million-token context window and up to 64,000 output tokens. Introductory pricing sits at $0.75 per million input tokens and $3.75 per million output tokens, matching its predecessor; the blog says it rises on January 1, 2027. Among benchmarks, Google cites 54.9 percent on HLE-Verified. CEO Sundar Pichai spoke of “significant leaps” in coding and reasoning, VentureBeat reported.
Flash Cyber: finding and fixing flaws
The cyber variant uses “long-running agentic loops,” per DeepMind, to inspect code, test findings and produce verified patches. Google reports a success rate above 70 percent for discovering vulnerabilities across 20 programming languages, 86.2 percent on the CyberGym benchmark and 47.2 percent on CWE-Bench. In Chrome’s codebase, the Chrome Security team said the model produced 2.6 times more correct patches than larger commercial models. Flash Cyber is initially available only through Google’s new “Fairwind” program for government agencies, critical infrastructure and software maintainers.
Context
The figures come largely from Google’s own testing and are not yet independently verified. Security researcher Raluca Ada Popa pointed to the core problem, per VentureBeat: scanning large codebases with AI is expensive, and defenders are overwhelmed.
Sources: Google Blog, Google DeepMind, VentureBeat, The Register.



















