AI Briefing
KO

Preview released: Detecting and fixing software vulnerabilities with CodeMender

·2026.07.22 00:00

Key point

Google has released a preview of CodeMender, which uses AI to automatically detect and fix software vulnerabilities.

Details

As adversarial AI threats attack code at increasing speed, security teams need machine-speed defense systems with automated code remediation capabilities. CodeMender is a managed code security agent that provides the ability to scan software for vulnerabilities and fix them directly.

CodeMender can be delivered through the Gemini Enterprise Agent Platform or deployed as a core component of AI Threat Defense. It also supports a multi-model approach that lets users select the optimal model based on cost, speed, and deep-scan performance, with support for third-party frontier models planned by the end of this year.

Key capabilities include:

  • Optimal model deployment: Choose from various models tailored to cost, speed, and deep-scan performance
  • Machine-scale automated remediation: Eliminates bottlenecks from manual validation and patching while maintaining the development process
  • Vulnerability prioritization: Verifies real-world exploitability by running and simulating PoC (Proof-of-Concept) exploits, addressing the most critical issues first

Built on research from Google DeepMind, CodeMender transforms vulnerability management from a manual task into an autonomous, high-speed system. The agent can integrate with existing CI/CD workflows or run directly in local development environments via a lightweight CLI client, while complying with enterprise-grade security guardrails such as secure routing through VPC and data isolation.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.