Google DeepMind has released Gemini 3.8 Flash, the company’s latest reasoning and coding model, alongside a dedicated cybersecurity variant called Gemini 3.8 Flash Cyber. The dual-variant approach marks a strategic shift in how Google is positioning its Flash family of models.
Flash Gets Smarter
Gemini 3.8 Flash represents a significant leap over its predecessor, 3.7 Flash, despite maintaining the same low price point of $0.75 per million input tokens and $3.75 per million output tokens. The model delivers substantial improvements across software engineering, agentic tasks, and multi-step reasoning in specialized domains.
On DeepSWE v1.1, a benchmark for long-horizon software engineering, Gemini 3.8 Flash outperforms most larger frontier models while costing only a fraction as much. The model also demonstrates strong performance on quantitative and professional reasoning tasks, achieving 54.9% on HLE-Verified—a benchmark testing multi-step reasoning across STEM, humanities, and professional fields.
What sets 3.8 Flash apart is its “diligence” on complex tasks. The model executes extra reasoning steps and calls tools iteratively when needed, making it more reliable for enterprise autonomy scenarios.
Enter Flash Cyber
The more intriguing release is Gemini 3.8 Flash Cyber, a cybersecurity-focused variant available exclusively through Google’s Fairwind Program for trusted defenders.
On CyberGym, the standard industry benchmark for vulnerability discovery, Gemini 3.8 Flash Cyber demonstrates frontier-level performance—outperforming both 3.5 Flash Cyber and significantly larger frontier models. Perhaps more impressively, on an internal benchmark spanning 20 programming languages, the model achieves a 70% success rate in discovering vulnerabilities across complex codebases.
The patching capability is equally compelling. On CWE-Bench, a challenging external benchmark for automated vulnerability fixes, Gemini 3.8 Flash Cyber achieves a 47.2% pass@1 rate—nearly matching a leading frontier model at 47.8%, but at a fraction of the cost.
Real-World Impact
Google is already using Flash Cyber internally with notable results. The Chrome Security team found that 3.8 Flash Cyber produced 2.6 times more correct patches than the best commercial models, despite being much smaller. Google’s Cloud Vulnerability Research team discovered a critical foundational vulnerability in less than two hours—a task that typically takes months of research.
Wiz’s testing showed that Gemini 3.8 Flash Cyber achieves 7.5-9.7% higher recall on internal penetration testing benchmarks at 2.3-5.2x lower cost compared to leading frontier models.
What This Means
The dual-variant strategy suggests Google is moving toward purpose-built models rather than one-size-fits-all approaches. By training the same foundational intelligence with different safety thresholds and deployment contexts, Google can serve both general-purpose and high-security use cases without compromise.
Gemini 3.8 Flash is available now through Google AI Studio, the Gemini API, and Google AI Pro/Ultra subscriptions. Flash Cyber requires enrollment in the Fairwind Program.