Big Sleep and CodeMender: Google's LLM bug hunter and its patching companion ============================================================================ Big Sleep is Google's LLM-based bug hunter, credited with 20 flaws in FFmpeg and ImageMagick in August 2025 and with catching SQLite CVE-2025-6965 before exploitation. CodeMender (preview) validates and patches, and Gemini 3.5 Flash Cyber (July 2026) found 55 confirmed V8 issues. None is sold as a product to the public. Maintainer: Google DeepMind and Project Zero Website: https://blog.google/innovation-and-ai/technology/safety-security/cybersecurity-updates-summer-2025/ Category: Frontier-lab and general scanners Targets: C / C++ open source, V8, SQLite, FFmpeg Approach: LLM agent evolved from Project Naptime; CodeMender validates with sandboxed PoCs and patches with a model-as-judge; Gemini 3.5 Flash Cyber trained on OSV and OSS-Fuzz data Access: Big Sleep internal; CodeMender preview on Google Cloud; Flash Cyber gated to governments and partners Status: Active Strengths: Pre-exploitation catch in SQLite. | Rigorous Project Zero disclosure. | CodeMender closes the loop to patches. Limits: Not available as a service. | C and C++ focus. | Not cryptography-aware. Firms using it: none listed Sources: https://blog.google/innovation-and-ai/technology/safety-security/cybersecurity-updates-summer-2025/ | https://cloud.google.com/security/codemender | https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/ Source page: https://agentsast.com/tools/big-sleep/ Compiled by: agentsast editors (https://agentsast.com/about/) Last reviewed: 2026-09-13