Mark RadarMARK RADAR
EN

Google Launches CodeMender AI Agent to Automate Security Patches

1 reports · First detected 2026-07-24 · Last active 2026-07-24

Software supply-chain attacks and flaws in open-source components have left engineering teams sorting through large volumes of security alerts, many of which never become practical exploits. Google’s CodeMender is designed to compress that workflow by using an AI agent to validate vulnerabilities, generate fixes and test patches. The approach could help developers focus scarce security resources on defects that pose an immediate, demonstrable threat.

As of July 24, 2026, Google has released CodeMender in public preview. The agent runs checks in an isolated environment, confirms whether a flaw can be exploited, and then creates and tests a patch before proposing it to developers. CodeMender uses Gemini 3.5 Flash as its default model, positioning the tool as a way for teams to prioritize verified risks and shorten the time between vulnerability discovery and remediation.

All Coverage

1 original reports

The Backstory

The history behind this event
Google Pushes Automated AI Vulnerability Patching as Core Cyber Defense2026-05-28 · 2 reports · similarity 0.82

Google says using AI merely to identify vulnerabilities is not enough to reverse the imbalance between attackers and defenders. The key is to automate patching at scale. Google is using Big Sleep to detect previously unknown vulnerabilities and CodeMender to advance code remediation, aiming to reduce manual workloads and the time systems remain exposed.

As of July 19, 2026, Google Cloud had launched an AI cybersecurity defense platform integrating Gemini, Wiz and Mandiant to prioritize vulnerability risks and deploy fixes. Google expects AI agents eventually to span the entire secure software development lifecycle (SSDLC), creating a round-the-clock automated defense process covering detection, assessment and remediation.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)