Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Google launches Gemini 3.8 Flash, limits Flash Cyber to vetted defenders

Google released Gemini 3.8 Flash for production API use alongside a cybersecurity variant for vulnerability discovery and patching that is limited to vetted defenders.

D
Sep 10, 2026 · 2 min read

Google DeepMind launched Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on September 2. The general model is available for production use, while the cybersecurity variant is reserved for vetted defenders.

Developers can access the general Gemini 3.8 Flash model through the Gemini API under the model ID gemini-3.8-flash. Google says the model supports a context window of up to 1 million tokens and text outputs of up to 64,000 tokens. It joins other specialized systems in the Gemini family, including Gemini Robotics 2.

Introductory pricing for Gemini 3.8 Flash is $0.75 per million input tokens and $3.75 per million output tokens through the end of 2026. Those rates apply to the general Flash model; the company has not published token-based pricing for Flash Cyber in the materials reviewed by DataPhoenix.

The Cyber variant is designed to detect vulnerabilities and generate patches. Rather than offering it through the general-purpose Gemini API, Google limits access to approved defenders through its Fairwind Program.

On the independent CWE-bench leaderboard, Gemini 3.8 Flash Cyber recorded a 47.2% pass@1 score and an average cost of $3.64 per rollout across 100 held-out audit-and-patch tasks. Claude Fable 5 recorded 47.8% at an average cost of $10.27 per rollout. CWE-bench verifies patches by checking that the original exploit no longer works while the project’s existing tests continue to pass.

Google also said Flash Cyber exceeded a 70% success rate in an internal vulnerability-discovery evaluation spanning complex codebases in 20 programming languages. The evaluation has not been independently reproduced in the sources reviewed. The company separately said its Chrome Security team obtained 2.6 times more correct vulnerability patches from Flash Cyber than from larger commercial models, but it did not disclose the comparators, test-set size or methodology.

Google’s launch announcement says the general and Cyber variants share the same foundational intelligence. The company said both were improved through long-running agentic loops that repeatedly evaluate results and refine the models. It also said it prioritized vulnerability fixing over offensive capabilities such as exploitation when designing the Cyber variant.

Flash Cyber has more permissive cybersecurity safeguards than the general model, according to Google, prompting tighter access controls. Under the Fairwind Program, organizations must undergo vetting and use user-level authentication, phishing-resistant multifactor authentication, access controls and employee-access tracking. The program limits use to internal security teams and prohibits redistribution or resale.

More news