CodeMender (Preview)
Google's security agent that finds vulnerabilities in a codebase, proves they are exploitable, and writes fixes, for teams on Google Cloud.

Details
- Scans a codebase, then tries to exploit each vulnerability it finds inside an isolated sandbox, so what reaches the report is confirmed rather than suspected
- Writes and tests a fix for each confirmed vulnerability, with a second model checking that the change does not break how the code behaves
- Covers C and C++, Go, Java, Python, Ruby, Rust, and TypeScript
- Available in preview through the Gemini Enterprise Agent Platform, or inside AI Threat Defense where Wiz orchestrates it, and connects to CI/CD pipelines, VS Code, and Antigravity
- The version built on Gemini 3.5 Flash Cyber is limited to a small set of governments and trusted partners for now, with wider access planned
Best for
getting a list of vulnerabilities that have already been confirmed as exploitable instead of a pile of maybes to triage
When to use it
a security backlog has grown past what the engineering team can work through by hand
Who benefits
security and platform engineering teams already running on Google Cloud
Staying informed is great. Staying ahead is better.
Pick a topic and leave with something you created.
Get new module drops and weekly AI strategy.