Google Cloud、コード脆弱性検出・修正ツール「CodeMender」をプレビュー公開
本文の状態
日本語全文を表示中
詳細モードで約9分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Google Cloud AI
Google Cloud は敵対的 AI 攻撃対策として、コードスキャンと自動修復機能を持つ管理型セキュリティエージェント「CodeMender」のプレビューを開始した。
AI深層分析を開く2026年8月4日 06:47
AI深層分析
キーポイント
CodeMender のプレビュー開始
Google はコードスキャンと修復機能を備えた管理型セキュリティエージェント「CodeMender」の利用を開始し、敵対的 AI 攻撃への即時対応を可能にする。
Gemini Enterprise Agent Platform との統合
CodeMender は Gemini Enterprise Agent Platform を通じて一般提供モデルにアクセスでき、AI と AI で戦う自動化された防御を実現する。
マルチモデルアプローチと将来の拡張
コスト、速度、深層スキャン性能を最適化するために複数のモデルを選択可能とし、年内にはサードパーティの最先端モデルにも対応予定である。
コードの修復とリスク低減
CodeMender は開発速度を犠牲にすることなく既存のセキュリティ問題を調査・修復し、受動的なスキャンから自動化されたコード修復へ移行させる。これによりゼロデイリスクを削減できる。
AI による自律的な脆弱性管理
Google DeepMind の AI 研究に基づき、開発者とセキュリティ担当者がソフトウェアの欠陥を自動スキャンし、実行可能なエクスプロイトで検証、テスト済みコード修正で修復する。
重要な引用
As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI.
CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense.
"At Salesforce, trust is our number one value, and protecting customer data means continually raising the bar for how we find, validate, and mitigate risks. CodeMender brings AI into a critical part of the security lifecycle by accelerating the path from validated vulnerability to tested fix. As AI reshapes the threat landscape, capabilities like this help strengthen resilience and give our customers the confidence to keep innovating," said Iain Mulholland, CISO, Salesforce.
"CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It doesn't just find theoretical flaws — it proves the immediate risk and delivers targeted, validated fixes that secure our environment without disrupting core business logic," said Scott Ponte, head, Security Operations, Robinhood.
編集コメントを表示
編集コメント
敵対的 AI の台頭に対応する実用的な防御手段として、CodeMender が注目される。特に「AI で AI を戦わせる」というアプローチを自動化ツールに具体化した点は、セキュリティ業界における重要な転換点と言えるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
敵対的 AI によるコード攻撃が加速する中、セキュリティチームは機械速度で対応できる防御策を講じる必要があります。具体的には、コードの自動修復を実現し、AI を用いて AI と戦う体制を整えることが不可欠です。
「CodeMender」は当社の管理型コードセキュリティエージェントであり、本日よりそのコードスキャンおよび修復機能をプレビューとして直接提供開始します。
CodeMender は、「Gemini Enterprise Agent Platform」を通じて一般利用可能なモデルへのアクセスを提供するほか、AI Threat Defense の中核コンポーネントとしてデプロイすることも可能です。
また、当社の「マルチモデルアプローチ」にも準拠しており、コスト、速度、詳細なスキャン性能の最適化に応じて適切なモデルを選択できます。今年後半にはサードパーティ製の最先端モデルへの対応も予定されています。
Google CodeMender を用いたコード脆弱性の自動検出と修復方法
*Gemini Enterprise Agent Platform における CodeMender の概要はこちらをご覧ください。*
CodeMender は、受動的なスキャンから自動化されたコード修復へと進化を促し、ゼロデイリスクの低減に貢献します。開発速度を犠牲にすることなく、既存のコードセキュリティ課題を検査・修復するために以下のような機能を提供します:
最適なモデルのデプロイ
コスト、速度、詳細なスキャン、コーディングパフォーマンスを最適化するために、複数のモデルから選択できます。
機械スケールでのリメディエーション自動化
手動検証やパッチ適用によるボトルネックを解消しつつ、開発者をプロセスに組み込んだまま、リメディエーションの効率化を実現します。
攻撃性に基づく優先順位付け
概念実証(PoC)の攻撃を実行し、シミュレーションを実施することで、コード内の脆弱性が実際に悪用可能か検証。最も重要な課題から順次対応するリソース配分が可能になります。
AI で脆弱性の発見と修正を実現
Google DeepMind の先駆的な AI 研究を基盤に生まれた CodeMender は、脆弱性管理を手作業のボトルネックから、自律的で高速なシステムへと変革します。開発者やセキュリティ担当者は、ソフトウェアを自動的にスキャンして欠陥を検出し、実行可能な攻撃によってその存在を確認し、検証済みのコード修正で即座に対処できます。
「Salesforce において信頼は最優先の価値です。顧客データを保護するためには、リスクの発見・検証・軽減の方法を常に高めていかなければなりません。CodeMender は AI をセキュリティライフサイクルの重要な段階に導入し、確認された脆弱性からテスト済みの修正へ至るまでの期間を大幅に短縮します。AI が脅威環境を変化させる中で、このような機能はレジリエンス(回復力)を強化し、顧客が安心してイノベーションを続けられるよう支えます」と、Salesforce の CISO である Iain Mulholland は述べています。
「CodeMender は、他の AI 搭載ツールが完全に見逃していた重大な脆弱性を一貫して特定します。単に理論上の欠陥を指摘するだけでなく、即座のリスクを実証し、コアとなるビジネスロジックを混乱させることなく環境を保護するための、ターゲットを絞られた検証済み修正を提供します。」
Robinhood のセキュリティ運用責任者である Scott Ponte はこう述べています。
「CodeMender は高速で包括的であり、検出から修正までのループを閉じることに真摯に取り組んでいます。これにより、チームは開発速度を落とすことなくソフトウェアサプライチェーンのセキュリティを強化できます。」
Palo Alto Networks の CTO 室シニア AI エンジニアである Ashwin Kannan はそう評価しています。
CodeMender エージェントの仕組み
CodeMender のハーンは、最新の Google DeepMind の研究成果に基づいて継続的に更新されるように微調整されています。これには、最新のエージェントスキル、セキュリティツール、システムプロンプトが含まれます。
「設計段階からセキュリティを考慮した」Agent Platform 上で動作する CodeMender は、エンタープライズグレードの組み込みガバナンスとセキュリティガードレールによって保護されています。具体的には、VPC を介した安全なトラフィックルーティング、データの分離と暗号化、そしてソースコードデータは一切保持しない(ゼロリテンション)という特徴があります。
エージェントとして、既存の継続的インテグレーションおよび継続的デリバリー(CI/CD)ワークフローに統合することも可能ですが、軽量なコマンドラインインターフェース(CLI)クライアントを使用してローカルの開発者環境で直接実行することもできます。
CodeMender を設定すれば、管理するサンドボックス内でコードのスキャンと分析も可能です。エージェントはコードリポジトリに接続し、VS Code や Antigravity といった開発ツールと連携して、自社製・オープンソース・サードパーティ製のソフトウェアを安全に分析します。
スキャン:柔軟なモデルスキャンで隠れた脆弱性を発見
CodeMender は主要な脆弱性クラスを検出し、コードリポジトリやアプリケーションが持つ 独自の文脈、目的、機能 を理解します。

セキュリティコンテキストを備えた CodeMender のハーンズは、静的解析やモデル単体のスキャンでは見逃されがちな高度な脆弱性の発見を支援します。メモリ破壊、インジェクション、Web セキュリティの問題、暗号化の欠陥、不十分なデータ処理など、検出が難しい脆弱性も対象となります。対応する主要プログラミング言語には C/C++、Go、Java、Python、Ruby、Rust、TypeScript が含まれます。
検証:エクスプロイトをシミュレーションしてノイズを削減
CodeMender は、脆弱性への対応前に実際にリスクがあることを証明することで、アラート疲れや誤検知を削減します。このエージェントは静的なコードパターン分析を超え、顧客が管理するサンドボックス内で構築・実行される攻撃用コードを用いて攻撃をシミュレーションします。

このエージェントは、概念実証用の攻撃コードを用いてセキュリティ欠陥が実際のリスクとなることを確認します。この重要な検証フェーズにより、セキュリティ担当者や開発者は誤検知を排除し、検証済みのリスクに優先順位をつけて対応できます。
Remediate: 自動的に修正コードの生成とテスト
危険なセキュリティ欠陥の特定は戦いの半分です。脆弱性が確認されると、CodeMender は自動的に安全なパッチを生成して問題を解決します。この修正は開発者ツールの直接にコード差分として提供されるため、既存の開発ワークフローに容易に統合できます。

CodeMender はさらに、LLM をジャッジとして活用することで、既存のアプリケーション機能に悪影響を与えないことを保証し、修正を強化しています。また、コードベース固有のコーディング規約やスタイルに関するコンテキストを提供することも可能で、これにより CodeMender がそのスタイルに合致したコードを生成できるようになります。開発者は引き続き完全なコントロール権を持ちます。リポジトリへのコミット前に、CodeMender によるパッチを手動でレビューし、承認するプロセスが必須です。
AI サイバー脅威防御における CodeMender
AI Threat Defense の一部として活用される場合、Wiz はエージェント型アプリケーションセキュリティを統括し、アプリケーションの分析を通じて調査の優先順位を決定します。CodeMender を呼び出してコードスキャン(近日公開予定)を実行したり、Wiz Security Graph 内でデプロイメントコンテキストを活用して検出結果を補強したり、Wiz Red Agent を起動して AI によるペネトレーションテストを行い、実際の攻撃可能性を実証したりします。これにより、チームは最もリスクの高い脆弱性への対応に集中することが可能になります。

Wiz は、AI 脅威防御におけるリメデーション(修正)の管理と拡大を担うコマンドセンターとして機能します。Wiz Green Agent がこのライフサイクルを調整し、セキュリティグラフから得たアプリケーションコンテキストを付与した高忠実度のパッチ生成とテストを CodeMender に指示します。この ワークフロー により、チームは前例のないスピードと精度で複雑な脆弱性を解決できるようになります。
CodeMender の始め方
マルチモデルアプローチ に一貫して、CodeMender はコスト、速度、そして深いスキャン性能の最適化をサポートします。
CodeMender は、一般提供されている Gemini モデルを Agent Platform を介して利用するか、AI 脅威防御 の中核コンポーネントとしてデプロイすることで使用できます。
なお、CodeMender に Gemini 3.5 Flash Cyber を組み合わせた機能は、限られた政府機関と信頼できるパートナー向けに独占的に提供されます。このアクセス権限は将来的に拡大していく予定です。
CodeMender は、継続的で自己修復型のエージェント型ソフトウェア開発ライフサイクルに向けた重要な一歩です。これは、コードが本番環境に展開される前に自動的にセキュリティ対策を施され、検証され、パッチ適用が行われる未来を実現するものです。
CodeMender に関する詳細やドキュメントは こちら で確認できます。
原文を表示
As adversarial AI threats accelerate attacks on code, security teams must counter them with machine-speed defenses that can automate code remediation and fight AI with AI.
CodeMender is our managed code security agent, and starting today, we're bringing its code scanning and remediation capabilities directly to you in preview.
CodeMender offers access to our generally available models via Gemini Enterprise Agent Platform, or it can be deployed as a core component of AI Threat Defense.
CodeMender also aligns with our multi-model approach, so you can choose the right model to optimize for cost, speed, and deep scanning performance. It will support third-party frontier model options later this year.
How to find and fix code vulnerabilities autonomously with Google CodeMender.
*Watch this overview of CodeMender in Gemini Enterprise Agent Platform.*
CodeMender can help you advance from passive scanning to automated code remediation, and reduce zero-day risk. It examines and remediates existing code security issues without sacrificing development velocity by:
- Deploying the best-fit model. You can choose from multiple models to optimize for costs, speed, deep scanning, and coding performance.
- Automating machine-scale remediation. You can now eliminate remediation bottlenecks caused by manual verification and patching, while keeping developers in the loop.
- Prioritizing fixes by exploitability. You can run proof-of-concept exploits and execute simulations to verify that vulnerabilities in the code are exploitable, and prioritize resources on fixing the most critical issues first.
Find and fix vulnerabilities with AI
Born from Google DeepMind's pioneering AI research, CodeMender transforms vulnerability management from a manual bottleneck into an autonomous, high-speed system. Your developers and security practitioners can automatically scan software for flaws, verify them with executable exploits, and remediate them with tested code fixes.
“At Salesforce, trust is our number one value, and protecting customer data means continually raising the bar for how we find, validate, and mitigate risks. CodeMender brings AI into a critical part of the security lifecycle by accelerating the path from validated vulnerability to tested fix. As AI reshapes the threat landscape, capabilities like this help strengthen resilience and give our customers the confidence to keep innovating,” said Iain Mulholland, CISO, Salesforce.
"CodeMender consistently identified critical vulnerabilities that our other AI-enabled tools completely missed. It doesn't just find theoretical flaws — it proves the immediate risk and delivers targeted, validated fixes that secure our environment without disrupting core business logic," said Scott Ponte, head, Security Operations, Robinhood.
"CodeMender is fast, comprehensive, and genuinely ambitious about closing the loop from detection to fix, enabling teams to secure their software supply chain without losing velocity," said Ashwin Kannan, principal AI engineer, Office of the CTO, Palo Alto Networks.
How the CodeMender agent works
We’ve fine-tuned CodeMender’s harness to be continuously updated with the latest Google DeepMind research, including the up-to-date agent skills, security tools, and system prompts.
Operating in the secure-by-design Agent Platform, CodeMender is protected by enterprise-grade, built-in governance and security guardrails, including secure traffic routing through your VPC, data isolation and encryption, and zero retention of source code data.
As an agent, it can integrate with existing continuous integration and continuous delivery (CI/CD) workflows, or run directly in local developer environments using a lightweight command-line interface (CLI) client.
You can also configure CodeMender to scan and analyze code in a sandbox that you manage. The agent connects to your code repositories and works with developer tools, such as VS Code and Antigravity, to safely analyze first-party, open-source, and third-party software.
Scan: Find hidden vulnerabilities with flexible model scanning
CodeMender scans for top vulnerability classes and understands the unique context, goals, and functionality of your software repositories and applications.

CodeMender’s harness with security context helps you discover sophisticated vulnerabilities that static and model-only scanning miss. These scans look for hard-to-find vulnerabilities like memory corruption, injection, web security issues, cryptographic flaws, and insecure data handling. CodeMender supports common software languages including C/C++, Go, Java, Python, Ruby, Rust, and TypeScript.
Verify: Simulate and verify exploits to reduce noise
CodeMender can help cut alert fatigue and false positives by proving a vulnerability presents a legitimate risk before fixing it. The agent goes beyond static code-pattern analysis by simulating an attack with exploit code it builds and runs in an isolated, customer-managed sandbox.

The agent uses this proof-of-concept exploit to verify that the security flaw poses a legitimate risk. This critical verification phase allows your security practitioners and developers to prioritize validated risks by eliminating false positives.
Remediate: Automatically generate and test code fixes
Identifying risky security flaws is only half the battle. Once a vulnerability is verified, CodeMender automatically generates a secure patch to resolve the issue. The fix is delivered as a code difference directly in developer tools, so it can be integrated into existing development workflows.

CodeMender further strengthens the fix by using LLM-as-a-judge to ensure it doesn’t disrupt existing application functionality. You can even provide context on your codebase's distinct coding conventions and styles so that CodeMender generates code that matches it. Developers remain in full control, manually reviewing and approving CodeMender's patches before any code is committed to the repository.
CodeMender in AI Threat Defense
When leveraged as part of AI Threat Defense, Wiz orchestrates agentic application security, analyzing applications to prioritize investigations. It calls CodeMender to scan code (coming soon), enrich findings within the Wiz Security Graph with deployment context, and trigger Wiz Red Agent for AI pentesting to prove exploitability, ensuring that teams focus on the highest-risk vulnerabilities.

Wiz serves as a command center for governing and scaling remediation in AI Threat Defense. The Wiz Green Agent orchestrates this lifecycle by directing CodeMender to generate and test high-fidelity patches enriched with application context from the Security Graph. This workflow empowers teams to resolve complex vulnerabilities with unprecedented speed and precision.
How to get started with CodeMender
Consistent with our multi-model approach, CodeMender can help you optimize for cost, speed, and deep scanning performance.
You can use CodeMender with our generally available Gemini models via Agent Platform, or deploy it as a core component of AI Threat Defense.
Separately, CodeMender with Gemini 3.5 Flash Cyber will be exclusively available to a small set of governments and trusted partners. We plan to expand this access over time.
CodeMender is a critical step towards a continuous, self-healing agentic software development lifecycle, a future where code is autonomously secured, validated, and patched before it ever hits production.
You can learn more about CodeMender and review the documentation here.
AI算出
主要ニュースainew評価標準
記事は Google DeepMind の技術を基盤とした新しいセキュリティエージェント「CodeMender」の詳細機能(自動修復、攻撃シミュレーション等)と導入事例を報じており、AI テクノロジーの具体的な実装と新機能を扱っているため ai_relevance は最高値。新規発表であり詳細な技術的説明があるため novelty は 0.75。検索意図として明確な製品名が含まれるがバージョン番号は含まれないため search_opportunity は 0.75。日本企業固有の導入事例や日本語一次情報がないため japan_relevance は 0.25。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 25
- 新規性
- 75
- 調べる価値
- 25
- 重複の少なさ
- 100
- 日本での有用性
- 25
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み