September 2 was cyber AI day. Google shipped Gemini 3.8 Flash Cyber, Anthropic locked Mythos 5.1 behind restricted access, and OpenAI admitted Astra hit its Critical threshold — same day. The HackerNews thread pulled 874 points.
Google’s entry is a security-specialized model that autonomously hunts vulnerabilities in code, then writes and validates the patches. Not a scanner wrapper — the model runs the whole loop itself.
The numbers Google is flexing
86.2% on the standard C/C++ vulnerability benchmark. 71% success on real-world discovery across 20+ languages. Google claims it beats Anthropic’s and OpenAI’s equivalents at autonomous vulnerability discovery — a Flash-sized model outgunning bigger frontier models. The Chrome team got 2.6x more correct patches with it than with larger commercial models; Google’s own researchers found a critical foundational bug in under 2 hours.
No public API, defenders only
There’s no API to sign up for. Access goes through the new Fairwind Program: governments, healthcare, critical infrastructure — 650+ organizations including CrowdStrike, Palo Alto Networks, and Snowflake. Google says it built for patching, not exploitation.
Three labs gating cyber models the same day is an admission: these models got good enough at finding bugs that open access is now the risk.
You Might Also Like
- Google Gemini Enterprise Gives Every ai Agent a Cryptographic id its Real Fight With Openai and Anthropic
- Google Gemini 3 6 Flash 3 5 Flash Lite 3 5 Flash Cyber two you can use one you Cant
- Openai Responding to the Next Frontier of Critical Cyber Capabilities the First Time Openai red Flags its own Model
- Anthropic to Acquire Stainless for 300m Buying the Developer Pipe to Openai and Google
- Microsoft Mdash Scores 88 45 on Cybergym Beating Anthropic Mythos and Openai gpt 5 5

Leave a comment