Artificial Intelligence

Google DeepMind’s New AI Agent Finds and Fixes Vulnerabilities 

The new product is called CodeMender and it can rewrite vulnerable code to prevent future exploits. 

AI hack

Google’s DeepMind artificial intelligence research lab this week unveiled an AI agent designed to autonomously find and fix vulnerabilities.

Google has several projects focusing on the use of AI for the discovery of vulnerabilities in software. The tech giant recently reported that its Big Sleep agent discovered a critical SQLite vulnerability and thwarted efforts to exploit it in the wild.

Its latest product is CodeMender, an AI agent that not only finds security holes but also patches them. The company argues that such tools are needed because as AI gets better at discovering flaws, it will be difficult for humans to keep up with patching. 

Related: CISO Conversations: John ‘Four’ Flynn, VP of Security and Privacy at Google DeepMind

Deepmind says CodeMender, which leverages Gemini DeepThink models, is capable of rewriting and securing existing code in order to eliminate entire classes of security bugs to prevent future exploits. 

CodeMender includes checks designed to ensure that the changes it makes do not cause regressions or other issues. 

Advertisement. Scroll to continue reading.

The AI agent can reason about code — understanding and predicting the behavior of a program without actually running it — and effectively validate changes through the use of advanced program analysis and multi-agent systems. 

Advanced program analysis includes static and dynamic analysis, fuzzing, differential testing, and SMT solvers to identify the root cause of vulnerabilities and architectural weaknesses. 

As for multi-agent systems, DeepMind explained, “We developed special-purpose agents that enable CodeMender to tackle specific aspects of an underlying problem. For example, CodeMender uses a large language model-based critique tool that highlights the differences between the original and modified code in order to verify that the proposed changes do not introduce regressions, and self-correct as needed.”

Over the past six months, CodeMender has provided 72 security fixes to open source projects, some of which have millions of lines of code. However, DeepMind says it’s being cautious and all patches are reviewed before being submitted. 

Related: Google Patches Gemini AI Hacks Involving Poisoned Logs, Search Results

Related: California Gov. Gavin Newsom Signs Bill Creating AI Safety Measures

Related: Salesforce AI Hack Enabled CRM Data Theft

Related Content

Application Security

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.

Artificial Intelligence

Claude Security, currently in public beta for Claude Enterprise customers, now runs codebase scans on Mythos 5.

Artificial Intelligence

Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment.

Cybercrime

We all know they’re watching us. But we don’t know who they are, nor why nor how they are doing it.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Artificial Intelligence

The action taken by OpenAI comes in light of the Hugging Face incident and the discovery of the Astra model’s advanced capabilities. 

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

Artificial Intelligence

Rapid7 warns that traditional patch cycles cannot keep pace with soaring vulnerability disclosures and faster exploitation, forcing defenders to prioritize exposure over severity scores.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version