Google launched Gemini 3.5 Flash Cyber on Tuesday, a security-focused model built to find and patch code vulnerabilities at a fraction of the cost of Anthropic's Mythos 5. In a benchmark run on the V8 JavaScript Engine, Flash Cyber surfaced 55 unique confirmed issues, versus 47 for the base Gemini 3.5 Flash and 36 for Claude Opus 4.6. The model is available first to governments and trusted partners through CodeMender, Google's security-focused coding agent.
The pitch is price. Google describes 3.5 Flash Cyber as a "cost-efficient and highly capable alternative" to larger security systems, aimed squarely at Anthropic's Mythos 5, which costs twice as much to run as Claude Opus 4.8. Because Flash Cyber is cheap to invoke, CodeMender can call it multiple times at high speed, letting its agents scan more code paths on each pass rather than reasoning once with a heavier model.
“cost-efficient and highly capable alternative”— Google, in a blog post announcing Gemini 3.5 Flash Cyber
On the CyberGym AI cybersecurity benchmark, Google says 3.5 Flash Cyber hit competitive performance against significantly larger models when invoked up to five times. That five-call ceiling is the pricing story compressed into a number: five invocations of a small model still comes in below one call to a compute-heavy system like Mythos 5, and in Google's testing, keeps finding new vulnerabilities each pass.
Key facts
- 01Gemini 3.5 Flash Cyber found 55 confirmed vulnerabilities in the V8 JavaScript Engine, versus 47 for base Gemini 3.5 Flash and 36 for Claude Opus 4.6.
- 02The model identified 10 issues that no other model in the comparison discovered.
- 03Anthropic's Mythos 5 costs 2x as much as Claude Opus 4.8 to run, the pricing gap Google is targeting.
- 043.5 Flash Cyber ships first to governments and trusted partners inside CodeMender, Google's security-focused coding agent.
- 05Google also released Gemini 3.6 Flash and 3.5 Flash-Lite, positioned as the most cost-effective model in the 3.5 series.
The V8 comparison is the sharpest data point. Beyond the 55-versus-36 headline against Opus 4.6, Google says Flash Cyber found 10 issues that no other model in the test discovered, a signal that repeated cheap invocations expose code paths a single heavier pass misses. Google notes the model kept surfacing new vulnerabilities the more it was called, which is the behavior CodeMender's agent loop is designed to exploit.
The competitive backdrop matters. Anthropic's Mythos 5 was released under its Project Glasswing initiative and has been adopted by Microsoft for internal security checks. Microsoft had its biggest Patch Tuesday this month after running Mythos across its codebases, a result that turned AI-driven vulnerability discovery from a research demo into a procurement line item. Every major model provider now needs a story here.
China's Z.ai has claimed its own model can compete with Mythos, and Google's release is the first major US-lab response with a specific cost-and-benchmark counter. Rather than chase Mythos on raw capability, Google is arguing the security-agent workflow itself favors small, fast, cheap models called many times inside a larger orchestration loop like CodeMender.
Flash Cyber launched alongside Gemini 3.6 Flash, which Google says brings improvements in coding and multimodal performance, and Gemini 3.5 Flash-Lite, positioned as the most cost-effective model in the 3.5 series. AI Chat Daily covered the 3.6 Flash and 3.5 Flash-Lite launches earlier this week; Flash Cyber is the security-specialized sibling in the same family, tuned specifically for the vulnerability-hunting workload.
The caveats are real. Google's benchmark numbers are Google's benchmark numbers, and Anthropic has not published a head-to-head response on V8 or CyberGym. Mythos 5's higher cost buys deeper single-pass reasoning, which matters on classes of vulnerabilities that require holding a large call graph in context at once. The five-invocation trick works best when the search space partitions cleanly; not every codebase does. Governments and enterprises evaluating Flash Cyber against Mythos will want their own internal bake-offs before switching security vendors on a blog-post benchmark.
The strategic read is that AI security is bifurcating into two model archetypes: expensive frontier reasoners like Mythos 5 that swing hard once, and cheap specialists like Flash Cyber that swing many times inside an agent loop. Google is betting the agent-orchestration side wins on cost-per-vulnerability-found, which is the metric buyers actually care about. If Flash Cyber's V8 numbers hold up in independent testing, Anthropic's pricing premium on Mythos becomes harder to defend, and CodeMender starts to look like the reference design for how security agents get built.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




