Mark RadarMARK RADAR
About
EN
Sign in

Google Pushes Automated AI Vulnerability Patching as Core Cyber Defense

2 reports · First detected 2026-04-27 · Last active 2026-05-28

Google says using AI merely to identify vulnerabilities is not enough to reverse the imbalance between attackers and defenders. The key is to automate patching at scale. Google is using Big Sleep to detect previously unknown vulnerabilities and CodeMender to advance code remediation, aiming to reduce manual workloads and the time systems remain exposed.

As of July 19, 2026, Google Cloud had launched an AI cybersecurity defense platform integrating Gemini, Wiz and Mandiant to prioritize vulnerability risks and deploy fixes. Google expects AI agents eventually to span the entire secure software development lifecycle (SSDLC), creating a round-the-clock automated defense process covering detection, assessment and remediation.

All Coverage

2 original reports

The Backstory

The history behind this event
Google Uses AI to Fix 1,072 Chrome Security Bugs in June2026-07-31 · 2 reports · similarity 0.83

Google’s Chrome security program has increasingly paired traditional code review and fuzzing with in-house artificial intelligence and large language models to uncover flaws that may have remained buried for years. The shift matters because Chrome is a gateway to online banking, commerce and corporate systems for billions of users, making faster vulnerability discovery and remediation a broad cybersecurity issue. Google said AI has materially changed the speed and scale of both detection and defense.

Google said on July 30 that Chrome 149 and Chrome 150, released to the stable channel on June 2 and June 30, 2026, respectively, fixed a combined 1,072 security bugs. That exceeded the 1,036 vulnerabilities repaired across the previous 23 Chrome milestones, compressing roughly two years of fixes into one month. The AI-assisted effort also uncovered a Chrome flaw that had remained undetected for 13 years, highlighting the technology’s growing role in finding long-lived weaknesses.

Google Launches CodeMender AI Agent to Automate Security Patches2026-07-24 · 1 reports · similarity 0.82

Software supply-chain attacks and flaws in open-source components have left engineering teams sorting through large volumes of security alerts, many of which never become practical exploits. Google’s CodeMender is designed to compress that workflow by using an AI agent to validate vulnerabilities, generate fixes and test patches. The approach could help developers focus scarce security resources on defects that pose an immediate, demonstrable threat.

As of July 24, 2026, Google has released CodeMender in public preview. The agent runs checks in an isolated environment, confirms whether a flaw can be exploited, and then creates and tests a patch before proposing it to developers. CodeMender uses Gemini 3.5 Flash as its default model, positioning the tool as a way for teams to prioritize verified risks and shorten the time between vulnerability discovery and remediation.

AI Emerges as Cybersecurity Double-Edged Sword as Google and Anthropic Assess Defenses and Threats2026-05-07 · 1 reports · similarity 0.80

Generative AI is reshaping both cyberattacks and defenses. Attackers can use it to automate malware development, gather intelligence and scale operations, while defenders can accelerate vulnerability analysis and threat tracking. Shane Huntley, chief technology officer at Google's Threat Intelligence Group, said the shift marked an important turning point for companies to redesign their cybersecurity strategies. The developments did not involve any transaction value.

The latest developments show that AI is increasing both the speed of attacks and the capabilities of defenders. Google warned that hackers could launch operations faster and at greater scale, while Anthropic's Claude Mythos model showed potential to uncover previously unknown vulnerabilities. The available information gave no specific release date, number of vulnerabilities or monetary figures. The current focus remains on validating model performance and building safeguards.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)