
Google Ships Gemini 3.8 Flash and a 'Cyber' Twin That Hunts Vulnerabilities
The new Flash flagship jumps to 90.8% on Terminal-Bench 2.1 and beats larger frontier models on long-horizon coding, while Gemini 3.8 Flash Cyber debuts under Google's restricted Fairwind program for governments.
Google has released Gemini 3.8 Flash, its most capable Flash-tier model and third Flash release in six weeks, alongside a cybersecurity-specialized variant — Gemini 3.8 Flash Cyber — available only through a new limited-access program for governments and trusted partners.
The workhorse gets serious
Gemini 3.8 Flash posts a striking benchmark profile for a mid-tier model: 90.8 percent on Terminal-Bench 2.1, up from 81.6 percent for 3.7 Flash, and results on DeepSWE v1.1's long-horizon agentic coding suite that outperform most larger frontier models — including, on several axes, models that cost an order of magnitude more per token.
Google is holding pricing at $0.75 per million input tokens and $3.75 output through December 31, after which rates double. The subtext is unambiguous: Flash is no longer the cheap tier — it is Google's volume play for the agentic era, where cost-per-completed-task matters more than cost-per-token. Consumers get the model via the Gemini app, AI Mode in Search, and Gemini in Sheets for Pro and Ultra subscribers.
The Cyber fork
The more consequential release may be the one most people cannot use. Gemini 3.8 Flash Cyber, optimized for offensive and defensive security tasks, launches exclusively through Google Fairwind — a vetted-access program for governments and selected partners. Google says it surpasses not only 3.5 Flash Cyber but significantly larger frontier models on security benchmarks.
The gated release reflects a hardening industry consensus: days earlier, OpenAI shipped GPT-6 Astra as its first model rated "critical" for cybersecurity capability, and its chief scientist has since called for industry-wide pacing. Cyber-capable models are now treated less like products and more like export-controlled goods — with access itself becoming the safety mechanism.
The cadence is the story
Three Flash releases in six weeks — 3.7, 3.8, plus the Cyber fork — illustrates the shipping tempo the frontier labs have settled into, even as safety essays call for slowdowns. For developers, the practical takeaway is simpler: the price-performance frontier keeps moving down-market. Tasks that required a flagship model at the start of the summer now run on a Flash model at a fraction of the cost — and the Flash models themselves are increasingly the agents, not the assistants.
Newsletter
Get Lanceum in your inbox
Weekly insights on AI and technology in Asia.
More in Research

Meta's Muse Spark 1.3 Reaches the Frontier: 75.4% on DeepSWE, 1M Context, and a Data-for-Discount Endpoint

Qwen3.8-Flash-Next: Alibaba Previews the Qwen4 Architecture With Hybrid Attention and 'Engram' Embeddings
