Skip to main content
Live
Main content

Google launches Gemini 3.5 Flash Cyber to undercut Anthropic's Mythos

The new security model runs at a fraction of Mythos 5's cost and found 55 confirmed bugs in V8, beating Claude Opus 4.6's 36.

Jaeden Schafer
Editor in Chief · · 4 min read
Google logo

Google launched Gemini 3.5 Flash Cyber on Tuesday, a security-focused model built to find and patch code vulnerabilities at a fraction of the cost of Anthropic's Mythos 5. In a benchmark run on the V8 JavaScript Engine, Flash Cyber surfaced 55 unique confirmed issues, versus 47 for the base Gemini 3.5 Flash and 36 for Claude Opus 4.6. The model is available first to governments and trusted partners through CodeMender, Google's security-focused coding agent.

The pitch is price. Google describes 3.5 Flash Cyber as a "cost-efficient and highly capable alternative" to larger security systems, aimed squarely at Anthropic's Mythos 5, which costs twice as much to run as Claude Opus 4.8. Because Flash Cyber is cheap to invoke, CodeMender can call it multiple times at high speed, letting its agents scan more code paths on each pass rather than reasoning once with a heavier model.

cost-efficient and highly capable alternative
Google, in a blog post announcing Gemini 3.5 Flash Cyber

On the CyberGym AI cybersecurity benchmark, Google says 3.5 Flash Cyber hit competitive performance against significantly larger models when invoked up to five times. That five-call ceiling is the pricing story compressed into a number: five invocations of a small model still comes in below one call to a compute-heavy system like Mythos 5, and in Google's testing, keeps finding new vulnerabilities each pass.

Key facts

  • 01Gemini 3.5 Flash Cyber found 55 confirmed vulnerabilities in the V8 JavaScript Engine, versus 47 for base Gemini 3.5 Flash and 36 for Claude Opus 4.6.
  • 02The model identified 10 issues that no other model in the comparison discovered.
  • 03Anthropic's Mythos 5 costs 2x as much as Claude Opus 4.8 to run, the pricing gap Google is targeting.
  • 043.5 Flash Cyber ships first to governments and trusted partners inside CodeMender, Google's security-focused coding agent.
  • 05Google also released Gemini 3.6 Flash and 3.5 Flash-Lite, positioned as the most cost-effective model in the 3.5 series.

The V8 comparison is the sharpest data point. Beyond the 55-versus-36 headline against Opus 4.6, Google says Flash Cyber found 10 issues that no other model in the test discovered, a signal that repeated cheap invocations expose code paths a single heavier pass misses. Google notes the model kept surfacing new vulnerabilities the more it was called, which is the behavior CodeMender's agent loop is designed to exploit.

The competitive backdrop matters. Anthropic's Mythos 5 was released under its Project Glasswing initiative and has been adopted by Microsoft for internal security checks. Microsoft had its biggest Patch Tuesday this month after running Mythos across its codebases, a result that turned AI-driven vulnerability discovery from a research demo into a procurement line item. Every major model provider now needs a story here.

China's Z.ai has claimed its own model can compete with Mythos, and Google's release is the first major US-lab response with a specific cost-and-benchmark counter. Rather than chase Mythos on raw capability, Google is arguing the security-agent workflow itself favors small, fast, cheap models called many times inside a larger orchestration loop like CodeMender.

Flash Cyber launched alongside Gemini 3.6 Flash, which Google says brings improvements in coding and multimodal performance, and Gemini 3.5 Flash-Lite, positioned as the most cost-effective model in the 3.5 series. AI Chat Daily covered the 3.6 Flash and 3.5 Flash-Lite launches earlier this week; Flash Cyber is the security-specialized sibling in the same family, tuned specifically for the vulnerability-hunting workload.

The caveats are real. Google's benchmark numbers are Google's benchmark numbers, and Anthropic has not published a head-to-head response on V8 or CyberGym. Mythos 5's higher cost buys deeper single-pass reasoning, which matters on classes of vulnerabilities that require holding a large call graph in context at once. The five-invocation trick works best when the search space partitions cleanly; not every codebase does. Governments and enterprises evaluating Flash Cyber against Mythos will want their own internal bake-offs before switching security vendors on a blog-post benchmark.

Related · from this week
Google says it disrupted the first AI-built zero-day exploit in the wild
Jaeden Schafer · 4 min read →

The strategic read is that AI security is bifurcating into two model archetypes: expensive frontier reasoners like Mythos 5 that swing hard once, and cheap specialists like Flash Cyber that swing many times inside an agent loop. Google is betting the agent-orchestration side wins on cost-per-vulnerability-found, which is the metric buyers actually care about. If Flash Cyber's V8 numbers hold up in independent testing, Anthropic's pricing premium on Mythos becomes harder to defend, and CodeMender starts to look like the reference design for how security agents get built.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Google logo
Security

Google says it disrupted the first AI-built zero-day exploit in the wild

GTIG flagged a 'hallucinated CVSS score' and textbook formatting in a Python exploit targeting 2FA on an open-source admin tool.

Jaeden Schafer4 min read
Google logo
Analysis

Gemini's Spark, Daily Brief, and chat sprawl expose an AI branding problem

Google's Gemini app now houses three separately branded features — a pattern Anthropic and OpenAI repeat, and Apple deliberately avoids.

Jaeden Schafer4 min read
Google logo
Careers

Google loses Gemini architects Adler and Pritzel to Anthropic

Two more Gemini researchers join a wave of defections to Anthropic and OpenAI, weeks after Google paid $2.7B to bring Noam Shazeer back.

Jaeden Schafer4 min read