This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Patch Me If You Can : Quand CodeMender prend le contrôle de votre stack

Download resources

About this session

Yan Bellerose, a Google security architect, traces the run-up to CodeMender, Google's AI tool for finding, proving and patching vulnerabilities, situating it against a widely discussed rival model the room nicknames 'Mythos'. He walks through the lineage: 2024's Project Naptime, which gave an AI agent a security researcher's skills and reached twenty times human speed; Big Sleep, which found a zero-day in SQLite and later pre-empted an attack Mandiant had flagged; and CodeMender's public launch in May 2026. He frames CodeMender as a 'harness' — tools, skills and prompts wrapped around a generic Gemini model — rather than a bespoke security model, and details its three stages: scan, verify with a sandboxed proof-of-concept exploit, and patch. He compares cost and accuracy across Gemini Flash Cyber, Fable and Mythos, contrasts results through Google's Agent Development Kit versus Cloud Code, and covers two-way context sharing with Wiz. He reports roughly 75% developer acceptance of CodeMender's patches inside Google. A short Q&A covers false-positive cost, the roughly 90% true-positive rate after verification, and harness-versus-tool effects on results.

Le délai moyen d’exploitation des vulnérabilités est passé de 500 jours à moins de 2 jours. Les équipes de développement et de sécurité peuvent-elles encore suivre le rythme ?
Dans cette session, nous vous présenterons CodeMender, l'agent IA de Google Cloud capable de détecter, prouver l'exploitabilité réelle et générer des correctifs sécurisés pour vos applications à la vitesse des machines. Venez découvrir comment transformer votre cycle de développement logiciel en un modèle auto-cicatrisant (self-healing SDLC) tout en garantissant la confidentialité totale de votre code source.

Key takeaways

  • Consider an LLM-based scan-verify-patch tool such as CodeMender when average exploit time has dropped under two days and manual triage cannot keep pace.
  • When evaluating a cyber-tuned model, compare cost per finding alongside detection rate; a smaller specialized model can match a larger general model's accuracy at a fraction of the token cost.
  • Wrap a generic model in a task-specific 'harness' (tools, skills, precise prompts) rather than defaulting to building or buying a bespoke security-tuned model.
  • Feed the tool infrastructure context (network segment, firewall rules, WAF configuration) so it prioritizes exploitable findings over theoretically serious ones.
  • Keep generated exploits, patches and logs local to your own repo or machine rather than the vendor's, and expect internal audit tools to flag locally-created exploit scripts.

Speakers

Yan Bellerose
Yan Bellerose
Cloud Security Architect · Google
What happens when you let a tech architect loose on ambitious business goals for more than 20 years? You get Yan Bellerose, Cyber Security Architect at Google! He has been turning ambitious business strategies into technical realities (and ensuring… Read moreRead less

What happens when you let a tech architect loose on ambitious business goals for more than 20 years? You get Yan Bellerose, Cyber Security Architect at Google! He has been turning ambitious business strategies into technical realities (and ensuring they don't become IT nightmares). His playground is cloud computing, cybersecurity, telecom and AI, where he crafts future-proof solutions that are as elegant as they are secure. As a leader, Yan fosters a culture of innovation, empowering his teams to not just fix today's problems, but to predict and neutralize tomorrow's digital bogeymen. He's a passionate believer in automation—because the best security is the kind that works tirelessly while the humans are out getting coffee.

Resources

Photos

Tags

More from GoSec 2026

Also from Yan Bellerose

On the same topic