Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and generate working patches for them.
The release arrives just three weeks after Gemini 3.7 Flash, marking Google’s third Flash-tier launch in six weeks, and both new models share the same underlying architecture while being tuned for different deployment scenarios.
Google Launches Gemini 3.8 Flash Cyber
The general-purpose Gemini 3.8 Flash targets long-horizon software engineering and agentic workloads, offering meaningful gains over 3.7 Flash while keeping the same introductory pricing of $0.75 per million input tokens and $3.75 per million output tokens.
On the DeepSWE v1.1 benchmark for complex, end-to-end engineering tasks, it reportedly outperforms several larger frontier models at a fraction of the cost, and it scores 54.9% on HLE-Verified, reflecting strong multi-step reasoning across technical and professional domains.
Google attributes these gains to the model’s willingness to take extra reasoning steps and call tools iteratively when tackling difficult problems, though this can increase token usage at higher effort settings.
The cybersecurity-focused Gemini 3.8 Flash Cyber is being made available exclusively to vetted security teams through Google’s new Fairwind Program, as announced in Google’s research publication, reflecting the sensitivity of a model trained to find exploitable flaws.
On CyberGym, a widely used industry benchmark for vulnerability discovery, the model reportedly surpasses both its predecessor, 3.5 Flash Cyber, and significantly larger frontier competitors.
Google also tested the model against an internal benchmark spanning twenty programming languages beyond the C/C++ focus of CyberGym, where it achieved a success rate exceeding 70%, a notable jump over prior versions.
| Model Variant | Primary Focus & Target Workloads | Key Benchmark Performance | Access & Deployment Model |
| Gemini 3.8 Flash | Long-horizon software engineering & agentic workflows | DeepSWE v1.1 frontier outperformance; 54.9% on HLE-Verified | General availability ($0.75 / $3.75 per 1M tokens) |
| Gemini 3.8 Flash Cyber | Autonomous vulnerability hunting & automated patching | >70% across 20 languages; 47.2% CWE-Bench pass@1 | Vetted security teams via Google Fairwind Program |
Rather than emphasizing exploitation capabilities, Google says it deliberately prioritized defensive patching from the outset.
On CWE-Bench, an external benchmark for automated fixes run by Collinear, Gemini 3.8 Flash Cyber posted a pass@1 score of 47.2%, nearly matching a leading frontier model’s 47.8% while running at a considerably lower cost.

Google states the model is already securing its own codebases. The Chrome Security team found it produced 2.6 times more correct vulnerability patches than larger commercial rivals, while security firm Wiz measured 7.5 to 9.7 percent higher recall on internal penetration-testing benchmarks at two to five times lower cost.
In one striking case, Google’s Cloud Vulnerability Research team used the model to uncover a critical foundational vulnerability in under two hours, a discovery process that typically takes months of manual research.
By pairing agentic reasoning with domain-specific cybersecurity training, Gemini 3.8 Flash Cyber signals Google’s push to give defenders an automated edge over attackers, even as broader access remains limited to trusted program participants for now.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

