Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

July 23, 2026

Google Makes CodeMender Available as Managed AI Security Agent

July 22, 2026

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

July 22, 2026
Facebook X (Twitter) Instagram
Thursday, July 23
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Google Makes CodeMender Available as Managed AI Security Agent
News

Google Makes CodeMender Available as Managed AI Security Agent

Team-CWDBy Team-CWDJuly 22, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Users of Google’s Gemini Enterprise Agent Platform and AI Threat Defense can leverage CodeMender, now a fully managed AI code security agent built for the enterprise, to find and fix vulnerabilities.

Developed by Google DeepMind, CodeMender was officially introduced in October 2025 primarily as an advanced security research project.

It initially offered capabilities such as autonomous, research-based software vulnerability discovery, debugging and patching.

The system utilized Gemini reasoning models alongside static and dynamic code analysis tools to perform deep root-cause analysis on codebase defects.

Rather than merely pointing out theoretical security issues, it focused on generating correct patches and automatically validating them to ensure they resolved vulnerabilities without causing regressions.

In its initial research phase, the DeepMind team said CodeMender also demonstrated proactive capabilities by successfully rewriting legacy codebase patterns to pre-emptively eliminate entire classes of vulnerabilities, resulting in the successful upstreaming of 72 security fixes to major open-source projects under human-in-the-loop oversight.

From Research Tool to Enterprise-Ready AI Code Security Agent

Now, Google has expanded CodeMender’s capabilities with its transition from a standalone research project to a fully managed, enterprise-ready AI code security agent integrated directly into Google Cloud’s infrastructure.

Rather than relying solely on code analysis, the agent now actively builds and runs proof-of-concept (PoC) exploits in customer-managed sandboxes to verify if vulnerabilities are truly exploitable.

It also delivers tested fixes directly to development pipelines as code differences for review, while introducing a large language model-as-a-judge mechanism to guarantee that these changes align with specific organizational rules and do not break core business logic.

CodeMender is now multi-model, allowing developers to choose from different Gemini models, such as Gemini 3.5 Flash, Gemini 3.1 Pro, or Gemini 3 Flash, to balance costs, speed and deep scanning needs.

“It will support third-party frontier model options later this year,” Google said in a statement on July 21.

Read more: Google Cloud’s New CISO Chris Betz on Integrating AI in Cyber Defenses

CodeMender: Current Features and Future Roadmap

Currently, enterprise customers can access CodeMender through the Google Cloud ecosystem.

It is available in public preview as a code security agent on the Gemini Enterprise Agent Platform, where it supports generally available models and integrates directly into local developer environments via a command line interface (CLI) and tools such as VS Code and the Antigravity desktop app.

CodeMender can also be deployed immediately as a core component of Google AI Threat Defense, working in tandem with Mandiant’s frontline expertise and Wiz’s contextual risk prioritization.

For security and control, features such as secure traffic routing through a customer’s Virtual Private Cloud, data isolation, encryption and zero retention of source code data are fully operational today.

At the preview stage, CodeMender officially supports scanning and remediating vulnerabilities across major software languages including C, C++, Go, Java, Python, Ruby, Rust and TypeScript or JavaScript, alongside popular enterprise frameworks like Django, Flask, React, Spring Boot and Express.

While Gemini 3.5 Flash is the default model, Gemini 3.1 Pro and Gemini 3 Flash are also available in preview.

Additionally, a highly specialized, security-tuned model called Gemini 3.5 Flash Cyber – specifically engineered within CodeMender to quickly identify, test and patch critical flaws – is currently in a limited-access pilot program, which Google is restricting exclusively to governments and trusted partners due to its powerful dual-use nature.

Several other features are slated to arrive soon, like the capability for Wiz to actively call on CodeMender to scan code in AI Threat Defense. This will allow Wiz’s Green Agent to orchestrate the remediation process directly.

Finally, Google is planning to roll out advanced enterprise governance features in the future, which will include robust user registration and identity management, advanced observability and audit logs and localized data residency controls.

Image credits: Koshiro K / Mijansk786 / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous Articlen8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
Next Article Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
Team-CWD
  • Website

Related Posts

News

Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories

July 23, 2026
News

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

July 22, 2026
News

TrickBot Ditches HTTP for DNS Tunneling in Latest Variant

July 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How cybercriminals are targeting content creators

November 26, 2025

Your information is on the dark web. What happens next?

January 13, 2026

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.