Gemini 3.8 Flash Ships with a Cyber Variant Google Gates to Vetted Defenders
Google has released Gemini 3.8 Flash, a reasoning and coding model priced identically to its predecessor, while restricting the specialized Cyber variant to vetted defenders via the new Fairwind Program.
Gemini 3.8 Flash arrives three weeks after version 3.7, maintaining the same introductory pricing of $0.75 per million input tokens and $3.75 per million output tokens. The model targets long-horizon software engineering and agentic tasks, claiming performance gains that approach larger frontier models on the DeepSWE v1.1 benchmark. In specialized domains, it outperforms previous iterations on Vals Finance Agent V2 and Harvey's Legal Agent Benchmark, while achieving a 54.9% score on HLE-Verified for multi-step reasoning across STEM and humanities. These improvements stem from a design choice where the model executes additional reasoning steps and iterative tool calls, potentially increasing token usage to maximize accuracy on complex prompts. Developers prioritizing compute efficiency can lower effort levels or continue using the fully supported 3.7 Flash.
The second release, Gemini 3.8 Flash Cyber, is not publicly available; access is limited to trusted government authorities, critical infrastructure operators, and software maintainers through the Fairwind Program. This variant focuses exclusively on defensive capabilities, specifically autonomous vulnerability discovery and automated patching, while omitting offensive exploitation tools. On the CyberGym benchmark, it surpasses both Gemini 3.5 Flash Cyber and significantly larger frontier models in finding vulnerabilities. An internal evaluation across 20 programming languages shows a success rate exceeding 70%. For patching, the model achieves a 47.2% pass@1 score on the external CWE-Bench, placing it on the Pareto frontier against a leading competitor's 47.8% at a significantly lower cost.
Deployment data indicates immediate integration within Google's security workflows. The Chrome Security team reported 2.6 times more correct patches compared to best-in-class commercial models, while Wiz observed a 7.5-9.7% higher recall on penetration testing benchmarks at 2.3-5.2x lower cost. Google's Cloud Vulnerability Research team utilized the model to identify a critical foundational vulnerability in under two hours, a task typically requiring months. Both variants include safeguards against CBRN misuse, with the Cyber variant employing specific mitigations to prevent offensive application while enabling comprehensive defensive analysis.