LLMs

Google launches Gemini 3.5 Flash Cyber to undercut Anthropic's pricey Mythos security model

Google's new cost-efficient AI security model competes with Anthropic's Mythos 5, finding more vulnerabilities in V8 JavaScript Engine at a fraction of the cost.

Last verified:

Gemini 3.5 Flash Cyber undercuts Mythos in the AI security market

According to The Verge AI, Google has unveiled Gemini 3.5 Flash Cyber, a purpose-built AI security model designed to identify and remediate code vulnerabilities at a fraction of the cost charged by Anthropic’s Mythos 5. The model represents Google’s direct response to the rising adoption of specialized security-focused LLMs, with Mythos 5 costing approximately twice as much per inference as Claude Opus 4.8. By positioning Flash Cyber as a lightweight, high-throughput alternative, Google is targeting organizations that need continuous vulnerability scanning without the expense of compute-intensive specialized models.

Performance against specialized competitors

Google reports that Gemini 3.5 Flash Cyber achieved competitive performance on the CyberGym AI cybersecurity benchmark when invoked up to five times—a critical detail that shifts the evaluation frame from single-pass accuracy to multi-pass discovery capability. In testing on the V8 JavaScript Engine, the model identified 55 confirmed unique issues, outperforming both Gemini 3.5 Flash (47 issues) and Claude Opus 4.6 (36 issues). Notably, Gemini 3.5 Flash Cyber discovered 10 vulnerabilities that neither competing model detected, demonstrating that repeated queries can surface novel attack surfaces and code paths.

This repeated-invocation strategy aligns with how CodeMender, Google’s security-focused coding agent, will deploy the model—calling it “multiple times at high speed and low cost.” The efficiency gain is substantial: Microsoft, which adopted Mythos 5 for its own security infrastructure, reported its largest Patch Tuesday of the month after deploying AI-driven vulnerability discovery. If Flash Cyber can deliver comparable or superior results at lower per-token cost and with faster iteration cycles, the operational economics shift significantly in favor of Google’s offering.

Limited availability and competitive landscape

The Verge AI notes that Gemini 3.5 Flash Cyber will initially be available only to governments and trusted partners through CodeMender, suggesting a phased rollout strategy. This exclusivity may reflect both regulatory considerations (government-backed security tools often face vetting) and a desire to stress-test the model at scale before public release. The competitive field is tightening: China’s Z.ai has also claimed parity with Mythos on security benchmarks, widening the gap between Anthropic’s cost-per-query advantage and its actual market adoption if cost becomes the primary decision lever.

Why This Matters

Organizations currently evaluating security-focused AI tools face a binary choice: adopt Mythos for specialized expertise at premium pricing, or experiment with multi-pass, lower-cost alternatives like Flash Cyber that may achieve equivalent or superior results through repeated invocation. For security teams operating under tight budgetary constraints—particularly in government and regulated industries—the availability of a cost-efficient alternative reshapes the vendor calculus. If Google’s benchmark results hold up under independent reproduction and CodeMender’s multi-call architecture proves effective in production, teams may shift away from Mythos not because it’s inferior, but because Flash Cyber’s per-issue cost is materially lower and the repeated-query model surfaces more vulnerabilities per dollar. This could accelerate Google’s share of the emerging AI security tooling market, even as Anthropic retains a premium positioning for single-pass, high-confidence scenarios.

Frequently Asked Questions

How does Gemini 3.5 Flash Cyber differ from Mythos 5?

Mythos 5 costs roughly twice as much as Claude Opus 4.8 and requires significant compute. Gemini 3.5 Flash Cyber is built for cost efficiency and can be called multiple times at scale, making it more economical for continuous vulnerability scanning.

What makes repeated invocations important for security scanning?

Calling the model up to five times allows it to explore different code paths and discover vulnerabilities that a single pass might miss. Google's version found 10 security issues that other models failed to detect.

Is this model available to everyone now?

Initially, it's available to governments and trusted partners through CodeMender, Google's security-focused coding agent. Broader availability has not been announced.

#security #vulnerability-detection #cost-efficiency #competitive-positioning