{"id":117716,"date":"2026-07-24T12:30:33","date_gmt":"2026-07-24T12:30:33","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/117716\/"},"modified":"2026-07-24T12:30:33","modified_gmt":"2026-07-24T12:30:33","slug":"google-gives-developers-an-ai-bug-hunter-that-also-writes-patches","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/117716\/","title":{"rendered":"Google gives developers an AI bug hunter that also writes patches"},"content":{"rendered":"<p>Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm they are exploitable, and generate fixes for developers to review.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/Google_CodeMender.webp\" class=\"aligncenter\" alt=\"Google CodeMender\" title=\"CodeMender\"\/><\/p>\n<p class=\"text-center\">(Source: Google)<\/p>\n<p>The company describes it as a response to <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/02\/24\/ai-in-cybercrime-research\/\" rel=\"nofollow noopener\" target=\"_blank\">attackers who are already using AI<\/a> to speed up their work, arguing that defenders need automation that moves at the same speed.<\/p>\n<p>\u201cCodeMender can help you advance from passive scanning to automated code remediation, and reduce zero-day risk,\u201d Google said.<\/p>\n<p>CodeMender is now available through Gemini Enterprise Agent Platform, using Google\u2019s generally available Gemini models, or as a component of AI Threat Defense, Google\u2019s AI-powered security platform. <\/p>\n<p>A separate version paired with <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/07\/22\/google-gemini-3-5-flash-cyber-model\/\" rel=\"nofollow noopener\" target=\"_blank\">Gemini 3.5 Flash Cyber<\/a> is limited to a small number of governments and trusted partners, with Google planning to expand access over time. Google plans to support third-party frontier models later this year.<\/p>\n<p>\u201cWe\u2019ve fine-tuned CodeMender\u2019s harness to be continuously updated with the latest Google DeepMind research, including the up-to-date agent skills, security tools, and system prompts,\u201d the company explained.<\/p>\n<p>\u201cOperating in the secure-by-design Agent Platform, CodeMender is protected by enterprise-grade, built-in governance and security guardrails, including secure traffic routing through your VPC, data isolation and encryption, and zero retention of source code data,\u201d Google added.<\/p>\n<p>How the agent works<\/p>\n<p>CodeMender runs in three stages. It first scans repositories for vulnerabilities that static tools often miss, including memory corruption, injection flaws, web security issues, cryptographic weaknesses, and insecure data handling. It supports C\/C++, Go, Java, Python, Ruby, Rust, and TypeScript.<\/p>\n<p>Second, it tries to confirm a flaw is worth acting on. Rather than stopping at a pattern match, CodeMender builds a proof-of-concept exploit and runs it in a sandbox the customer controls, a step Google says cuts down on false positives.<\/p>\n<p>Once a flaw is confirmed, the agent writes a patch and checks it with a model acting as judge, meant to catch cases where a fix breaks something else in the application. The patch reaches a developer as a code diff, and no change reaches a repository without manual approval.<\/p>\n<p>When deployed within AI Threat Defense, CodeMender works alongside Wiz to link vulnerabilities with deployment context and trigger automated penetration testing. <\/p>\n<p>\u201cCodeMender is a critical step towards a continuous, self-healing agentic software development lifecycle, a future where code is autonomously secured, validated, and patched before it ever hits production,\u201d the company <a href=\"https:\/\/cloud.google.com\/blog\/products\/identity-security\/find-and-fix-software-vulnerabilities-with-codemender\" target=\"_blank\" rel=\"nofollow noopener\">concluded<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Google has launched a preview of CodeMender, an AI agent built to scan code for security flaws, confirm&hellip;\n","protected":false},"author":2,"featured_media":34741,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[24,5189,313,132,1429,13709],"class_list":["post-117716","post","type-post","status-publish","format-standard","has-post-thumbnail","category-google","tag-ai","tag-code","tag-cybersecurity","tag-google","tag-google-ai","tag-vulnerability-management"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/117716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=117716"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/117716\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/34741"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=117716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=117716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=117716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}