SIGNAL
Tracking the global AI frontier — labs · research · agents · policy
Frontier Signal
Practice

Now in preview: Find and fix software vulnerabilities with CodeMender

As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI. CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview. CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense. CodeMende

Now in preview: Find and fix software vulnerabilities with CodeMender
Primary source cloud.google.com ↗

Published July 21, 2026 · Category: AI Practice

Overview

As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI.

CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview.

CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense

CodeMender also aligns with our multi-model approach, so you can choose the right model to optimize for cost, speed, and deep scanning performance. It will support third-party frontier model options later this year.

How to find and fix code vulnerabilities autonomously with Google CodeMender.

Watch this overview of CodeMender in Gemini Enterprise Agent Platform.

CodeMender can help you advance from passive scanning to automated code remediation, and reduce zero-day risk. It examines and remediates existing code security issues without sacrificing development velocity by:

  • Deploying the best-fit model. You can choose from multiple models to optimize for costs, speed, deep scanning, and coding performance.

  • Automating machine-scale remediation. You can now eliminate remediation bottlenecks caused by manual verification and patching, while keeping developers in the loop.

  • Prioritizing fixes by exploitability. You can run proof-of-concept exploits and execute simulations to verify that vulnerabilities in the code are exploitable, and prioritize resources on fixing the most critical issues first.

Find and fix vulnerabilities with AI

Born from Google DeepMind's pioneering AI research, CodeMender transforms vulnerability management from a manual bottleneck into an autonomous, high-speed system. Your developers and security practitioners can automatically scan software for flaws, verify them with executable exploits, and remediate them with tested code fixes. 

“At Salesforce, trust is our number one value, and protecting customer data means continually raising the bar for how we find, validate, and mitigate risks. CodeMender brings AI into a critical part of the security lifecycle by accelerating the path from validated vulnerability to tested fix. As AI reshapes the threat landscape, capabilities like this help strengthen resilience and give our customers the confidence to keep innovating,” said Iain Mulholland, CISO, Salesforce.

"CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It doesn't just find theoretical flaws — it proves the immediate risk and delivers targeted, validated fixes that secure our environment without disrupting core business logic," said Scott Ponte, head, Security Operations, Robinhood. 

"CodeMender is fast, comprehensive, and genuinely ambitious about closing the loop from detection to fix, enabling teams to secure their software supply chain without losing velocity," said Ashwin Kannan, principal AI engineer, Office of the CTO, Palo Alto Networks.

How the CodeMender agent works

We’ve fine-tuned CodeMender’s harness to be continuously updated with the latest Google DeepMind research, including the up-to-date agent skills, security tools, and system prompts. 

Operating in the secure-by-design Agent Platform, CodeMender is protected by enterprise-grade, built-in governance and security guardrails, including secure traffic routing through your VPC, data isolation and encryption, and zero retention of source code data.

As an agent, it can integrate with existing continuous integration and continuous delivery (CI/CD) workflows, or run directly in local developer environments using a lightweight command-line interface (CLI) client. 

You can also configure CodeMender to scan and analyze code in a sandbox that you manage. The agent connects to your code repositories and works with developer tools, such as VS Code and Antigravity, to safely analyze first-party, open-source, and third-party software.

Scan: Find hidden vulnerabilities with flexible model scanning 

CodeMender scans for top vulnerability classes and understands the unique context, goals, and functionality of your software repositories and applications.

2

Scan: Discovered new vulnerabilities and categorized by severity and type.

CodeMender’s harness with security context helps you discover sophisticated vulnerabilities that static and model-only scanning miss. These scans look for hard-to-find vulnerabilities like memory corruption, injection, web security issues, cryptographic flaws, and insecure data handling. CodeMender supports common software languages including C/C++, Go, Java, Python, Ruby, Rust, and TypeScript.

Verify: Simulate and verify exploits to reduce noise

CodeMender can help cut alert fatigue and false positives by proving a vulnerability presents a legitimate risk before fixing it. The agent goes beyond static code-pattern analysis by simulating an attack with exploit code it builds and runs in an isolated, customer-managed sandbox.

Details

3

Verify: Creates verification plan and builds and tests exploits in your sandbox environment.

The agent uses this proof-of-concept exploit to verify that the security flaw poses a legitimate risk. This critical verification phase allows your security practitioners and developers to prioritize validated risks by eliminating false positives.

Remediate: Automatically generate and test code fixes

Identifying risky security flaws is only half the battle. Once a vulnerability is verified, CodeMender automatically generates a secure patch to resolve the issue. The fix is delivered as a code difference directly in developer tools, so it can be integrated into existing development workflows.

4

Remediate: Generates and tests code fix with code diff for developer review and approval.

CodeMender further strengthens the fix by using LLM-as-a-judge to ensure it doesn’t disrupt existing application functionality. You can even provide context on your codebase's distinct coding conventions and styles so that CodeMender generates code that matches it. Developers remain in full control, manually reviewing and approving CodeMender's patches before any code is committed to the repository.

CodeMender in AI Threat Defense

When leveraged as part of AI Threat Defense, Wiz orchestrates agentic application security, analyzing applications to prioritize investigations. It calls CodeMender to scan code (coming soon), enrich findings within the Wiz Security Graph with deployment context, and trigger Wiz Red Agent for AI pentesting to prove exploitability, ensuring that teams focus on the highest-risk vulnerabilities.

AITD Wheel - Copy of Final - BLOG-ALT_AIThreatChart_2436x1200_v2

Through Wiz, AI Threat Defense calls CodeMender to scan code, enrich findings, and trigger AI pentesting.

Wiz serves as a command center for governing and scaling remediation in AI Threat Defense. The Wiz Green Agent orchestrates this lifecycle by directing CodeMender to generate and test high-fidelity patches enriched with application context from the Security Graph. This workflow empowers teams to resolve complex vulnerabilities with unprecedented speed and precision.

How to get started with CodeMender

Consistent with our multi-model approach, CodeMender can help you optimize for cost, speed, and deep scanning performance.

You can use CodeMender with our generally available Gemini models via Agent Platform, or deploy it as a core component of AI Threat Defense.

Separately, CodeMender with Gemini 3.5 Flash Cyber will be exclusively available to a small set of governments and trusted partners. We plan to expand this access over time.

CodeMender is a critical step towards a continuous, self-healing agentic software development lifecycle, a future where code is autonomously secured, validated, and patched before it ever hits production. 

You can learn more about CodeMender and review the documentation here.

Source

Originally published at cloud.google.com.

Related Articles

F
Frontier Signal Desk

Frontier Signal tracks the global AI frontier — labs, research, agents, creation tools and real-world practice — straight from primary sources. Tip the desk: editorial@news.tunx.ai

Email the desk →
From our network: explore the AI assistant platform behind this site. Visit tunx.ai →
Note: This story is aggregated and summarized from the primary source linked above; the original publisher retains all rights. Details may evolve after publication — always confirm against the source. Nothing here is professional, legal or investment advice.

Related Stories

More from Practice →