<div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI.</span></p> <p><a href="https://cloud.google.com/security/codemender">CodeMender</a> is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview.</p> <p><span style="vertical-align: baseline;">CodeMender offers access to our generally available models via </span><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender"><span style="text-decoration: underline; vertical-align: baseline;">Gemini Enterprise Agent Platform</span></a><span style="vertical-align: baseline;">, or it can be deployed as a core component of </span><a href="https://cloud.google.com/security/ai-threat-defense"><span style="text-decoration: underline; vertical-align: baseline;">AI Threat Defense</span></a><span style="vertical-align: baseline;">. </span></p> <p><span style="vertical-align: baseline;">CodeMender also aligns with our </span><a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-next-26-why-we-re-multicloud-and-multi-ai"><span style="text-decoration: underline; vertical-align: baseline;">multi-model approach</span></a><span style="vertical-align: baseline;">, so you can choose the right model to optimize for cost, speed, and deep scanning performance. It will support third-party frontier model options later this year.</span></p></div> <div class="block-video"> <div class="article-module article-video "> <figure> <a class="h-c-video h-c-video--marquee" href="https://youtube.com/watch?v=4DJD3RHOnPA" data-glue-modal-trigger="uni-modal-4DJD3RHOnPA-" data-glue-modal-disabled-on-mobile="true"> <div class="article-video__aspect-image" style="background-image: url(https://storage.googleapis.com/gweb-cloudblog-publish/images/1_sg64BeM.max-1000x1000.png);"> <span class="h-u-visually-hidden">How to find and fix code vulnerabilities autonomously with Google CodeMender.</span> </div> <svg role="img" class="h-c-video__play h-c-icon h-c-icon--color-white"> <use xlink:href="#mi-youtube-icon"></use> </svg> </a> <figcaption class="article-video__caption h-c-page"> <h4 class="h-c-headline h-c-headline--four h-u-font-weight-medium h-u-mt-std">Watch this overview of CodeMender in Gemini Enterprise Agent Platform.</h4> </figcaption> </figure> </div> <div class="h-c-modal--video" data-glue-modal="uni-modal-4DJD3RHOnPA-" data-glue-modal-close-label="Close Dialog"> <a class="glue-yt-video" data-glue-yt-video-autoplay="true" data-glue-yt-video-height="99%" data-glue-yt-video-vid="4DJD3RHOnPA" data-glue-yt-video-width="100%" href="https://youtube.com/watch?v=4DJD3RHOnPA" ng-cloak> </a> </div> </div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">CodeMender can help you advance from passive scanning to automated code remediation, and reduce zero-day risk. It examines and remediates existing code security issues without sacrificing development velocity by:</span></p> <ul> <li aria-level="1" style="list-style-type: disc; vertical-align: baseline;"> <p role="presentation"><strong style="vertical-align: baseline;">Deploying the best-fit model</strong><span style="vertical-align: baseline;">. You can choose from multiple models to optimize for costs, speed, deep scanning, and coding performance.</span></p> </li> <li aria-level="1" style="list-style-type: disc; vertical-align: baseline;"> <p role="presentation"><strong style="vertical-align: baseline;">Automating machine-scale remediation</strong><span style="vertical-align: baseline;">. You can now eliminate remediation bottlenecks caused by manual verification and patching, while keeping developers in the loop.</span></p> </li> <li aria-level="1" style="list-style-type: disc; vertical-align: baseline;"> <p role="presentation"><strong style="vertical-align: baseline;">Prioritizing fixes by exploitability</strong><span style="vertical-align: baseline;">. You can run proof-of-concept exploits and execute simulations to verify that vulnerabilities in the code are exploitable, and prioritize resources on fixing the most critical issues first.</span></p> </li> </ul> <h3><strong style="vertical-align: baseline;">Find and fix vulnerabilities with AI</strong></h3> <p><span style="vertical-align: baseline;">Born from </span><a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">Google DeepMind's pioneering AI research</span></a><span style="vertical-align: baseline;">, CodeMender transforms vulnerability management from a manual bottleneck into an autonomous, high-speed system. Your developers and security practitioners can automatically scan software for flaws, verify them with executable exploits, and remediate them with tested code fixes. </span></p> <p><span style="vertical-align: baseline;">“At Salesforce, trust is our number one value, and protecting customer data means continually raising the bar for how we find, validate, and mitigate risks. CodeMender brings AI into a critical part of the security lifecycle by accelerating the path from validated vulnerability to tested fix. As AI reshapes the threat landscape, capabilities like this help strengthen resilience and give our customers the confidence to keep innovating,” said Iain </span><span style="vertical-align: baseline;">Mulholland, CISO, Salesforce</span><span style="vertical-align: baseline;">.</span></p> <p><span style="vertical-align: baseline;">"CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It doesn't just find theoretical flaws — it proves the immediate risk and delivers targeted, validated fixes that secure our environment without disrupting core business logic," said Scott Ponte, head, Security Operations, Robinhood. </span></p> <p><span style="vertical-align: baseline;">"CodeMender is fast, comprehensive, and genuinely ambitious about closing the loop from detection to fix, enabling teams to secure their software supply chain without losing velocity," said Ashwin Kannan, principal AI engineer, Office of the CTO, Palo Alto Networks.</span></p> <h3><strong style="vertical-align: baseline;">How the CodeMender agent works</strong></h3> <p><span style="vertical-align: baseline;">We’ve fine-tuned CodeMender’s harness to be continuously updated with the latest Google DeepMind research, including the up-to-date agent skills, security tools, and system prompts. </span></p> <p><span style="vertical-align: baseline;">Operating in the secure-by-design Agent Platform, CodeMender is protected by enterprise-grade, built-in governance and security guardrails, including secure traffic routing through your VPC, data isolation and encryption, and zero retention of source code data.</span></p> <p><span style="vertical-align: baseline;">As an agent, it can integrate with existing continuous integration and continuous delivery (CI/CD) workflows, or run directly in local developer environments using a lightweight command-line interface (CLI) client. </span></p> <p><span style="vertical-align: baseline;">You can also configure CodeMender to scan and analyze code in a sandbox that you manage. The agent connects to your code repositories and works with developer tools, such as </span><a href="https://docs.cloud.google.com/code/docs/vscode/install"><span style="text-decoration: underline; vertical-align: baseline;">VS Code</span></a><span style="vertical-align: baseline;"> and </span><a href="https://antigravity.google/" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">Antigravity</span></a><span style="vertical-align: baseline;">, to safely analyze first-party, open-source, and third-party software.</span></p> <h3><strong style="vertical-align: baseline;">Scan: Find hidden vulnerabilities with flexible model scanning </strong></h3> <p><span style="vertical-align: baseline;">CodeMender scans for top vulnerability classes and understands the </span><a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-how-ai-leverages-deep-context-defenders-advantage"><span style="text-decoration: underline; vertical-align: baseline;">unique context, goals, and functionality</span></a><span style="vertical-align: baseline;"> of your software repositories and applications.</span></p></div> <div class="block-image_full_width"> <div class="article-module h-c-page"> <div class="h-c-grid"> <figure class="article-image--large h-c-grid__col h-c-grid__col--6 h-c-grid__col--offset-3 " > <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2_LNSezkk.max-1000x1000.png" alt="2"> </a> <figcaption class="article-image__caption "><p data-block-key="c7u8w">Scan: Discovered new vulnerabilities and categorized by severity and type.</p></figcaption> </figure> </div> </div> </div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">CodeMender’s harness with security context helps you discover sophisticated vulnerabilities that static and model-only scanning miss. These scans look for hard-to-find vulnerabilities like memory corruption, injection, web security issues, cryptographic flaws, and insecure data handling. CodeMender supports common software languages including C/C++, Go, Java, Python, Ruby, Rust, and TypeScript.</span></p> <h3><strong style="vertical-align: baseline;">Verify: Simulate and verify exploits to reduce noise</strong></h3> <p><span style="vertical-align: baseline;">CodeMender can help cut alert fatigue and false positives by proving a vulnerability presents a legitimate risk before fixing it. The agent goes beyond static code-pattern analysis by simulating an attack with exploit code it builds and runs in an isolated, customer-managed sandbox.</span></p></div> <div class="block-image_full_width"> <div class="article-module h-c-page"> <div class="h-c-grid"> <figure class="article-image--large h-c-grid__col h-c-grid__col--6 h-c-grid__col--offset-3 " > <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_OEvpSjA.max-1000x1000.png" alt="3"> </a> <figcaption class="article-image__caption "><p data-block-key="c7u8w">Verify: Creates verification plan and builds and tests exploits in your sandbox environment.</p></figcaption> </figure> </div> </div> </div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">The agent uses this proof-of-concept exploit to verify that the security flaw poses a legitimate risk. This critical verification phase allows your security practitioners and developers to prioritize validated risks by eliminating false positives.</span></p> <h3><strong style="vertical-align: baseline;">Remediate: Automatically generate and test code fixes</strong></h3> <p><span style="vertical-align: baseline;">Identifying risky security flaws is only half the battle. Once a vulnerability is verified, CodeMender automatically generates a secure patch to resolve the issue. The fix is delivered as a code difference directly in developer tools, so it can be integrated into existing development workflows.</span></p></div> <div class="block-image_full_width"> <div class="article-module h-c-page"> <div class="h-c-grid"> <figure class="article-image--large h-c-grid__col h-c-grid__col--6 h-c-grid__col--offset-3 " > <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/4_LlL5FCA.max-1000x1000.png" alt="4"> </a> <figcaption class="article-image__caption "><p data-block-key="c7u8w">Remediate: Generates and tests code fix with code diff for developer review and approval.</p></figcaption> </figure> </div> </div> </div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">CodeMender further strengthens the fix by using LLM-as-a-judge to ensure it doesn’t disrupt existing application functionality. You can even provide context on your codebase's distinct coding conventions and styles so that CodeMender generates code that matches it. Developers remain in full control, manually reviewing and approving CodeMender's patches before any code is committed to the repository.</span></p> <h3><strong style="vertical-align: baseline;">CodeMender in AI Threat Defense</strong></h3> <p><span style="vertical-align: baseline;">When leveraged as part of </span><a href="https://cloud.google.com/security/ai-threat-defense"><span style="text-decoration: underline; vertical-align: baseline;">AI Threat Defense</span></a><span style="vertical-align: baseline;">, Wiz orchestrates agentic application security, analyzing applications to prioritize investigations. It calls CodeMender to scan code (coming soon), enrich findings within the </span><a href="https://www.wiz.io/lp/wiz-security-graph" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">Wiz Security Graph</span></a><span style="vertical-align: baseline;"> with deployment context, and trigger </span><a href="https://www.wiz.io/solutions/red-agent" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">Wiz Red Agent</span></a><span style="vertical-align: baseline;"> for AI pentesting to prove exploitability, ensuring that teams focus on the highest-risk vulnerabilities.</span></p></div> <div class="block-image_full_width"> <div class="article-module h-c-page"> <div class="h-c-grid"> <figure class="article-image--large h-c-grid__col h-c-grid__col--6 h-c-grid__col--offset-3 " > <img src="https://storage.googleapis.com/gweb-cloudblog-publish/original_images/AITD_Wheel_-_Copy_of_Final_-_BLOG-ALT_AIThreatChart_2436x1200_v2.gif" alt="AITD Wheel - Copy of Final - BLOG-ALT_AIThreatChart_2436x1200_v2"> </a> <figcaption class="article-image__caption "><p data-block-key="r3bx6">Through Wiz, AI Threat Defense calls CodeMender to scan code, enrich findings, and trigger AI pentesting.</p></figcaption> </figure> </div> </div> </div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">Wiz serves as a command center for governing and scaling remediation in AI Threat Defense. The </span><a href="https://www.wiz.io/blog/introducing-wiz-green-agent" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">Wiz Green Agent</span></a><span style="vertical-align: baseline;"> orchestrates this lifecycle by directing CodeMender to generate and test high-fidelity patches enriched with application context from the Security Graph. This </span><a href="https://www.wiz.io/blog/introducing-wiz-workflows" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">workflow</span></a><span style="vertical-align: baseline;"> empowers teams to resolve complex vulnerabilities with unprecedented speed and precision.</span></p> <h3><strong style="vertical-align: baseline;">How to get started with CodeMender</strong></h3> <p><span style="vertical-align: baseline;">Consistent with our </span><a href="https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-next-26-why-we-re-multicloud-and-multi-ai"><span style="text-decoration: underline; vertical-align: baseline;">multi-model approach</span></a><span style="vertical-align: baseline;">, CodeMender can help you optimize for cost, speed, and deep scanning performance.</span></p> <p><span style="vertical-align: baseline;">You can use CodeMender with our generally available Gemini models via </span><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender"><span style="text-decoration: underline; vertical-align: baseline;">Agent Platform</span></a><span style="vertical-align: baseline;">, or deploy it as a core component of </span><a href="https://cloud.google.com/security/ai-threat-defense"><span style="text-decoration: underline; vertical-align: baseline;">AI Threat Defense</span></a><span style="vertical-align: baseline;">.</span></p> <p><span style="vertical-align: baseline;">Separately, CodeMender with </span><a href="https://blog.google/innovation-and-ai/models-and-research/gemini-models/gemini-3-6-flash-3-5-flash-lite-3-5-flash-cyber/" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">Gemini 3.5 Flash Cyber</span></a><span style="vertical-align: baseline;"> will be exclusively available to a small set of governments and trusted partners. We plan to expand this access over time.</span></p> <p><span style="vertical-align: baseline;">CodeMender is a critical step towards a continuous, self-healing agentic software development lifecycle, a future where code is autonomously secured, validated, and patched before it ever hits production. </span></p> <p><span style="vertical-align: baseline;">You can learn more about CodeMender and review the documentation </span><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/codemender"><span style="text-decoration: underline; vertical-align: baseline;">here</span></a><span style="vertical-align: baseline;">. </span></p></div> Maestro News, gelişmeyi Maestro Dev ekseninde — yazılım, yapay zekâ, bulut ve ürün teslimatı — özgün dilde yeniden çerçeveliyor.
21 Temmuz 2026 15:003 dk okuma