Hercules: On-Premises AI Vulnerability Model, Ranked #1 on CyberGym
In light of the exponential increase in nation state security threats that demand deep expertise, Dream built Hero, a sovereign-grade, autonomous modular cyber-defense research team. This research team is powered by Hercules, a globally top-ranked defensive cyber model that, combined with Hero's autonomous multi-agent system harness, drives deep expertise across vulnerability assessment, malware unpacking, firmware validation and more.
Together, they help scale the security teams that defend government and critical infrastructure at scale.
For example, its vulnerability discovery and elimination capabilities have identified over 1,000 validated, exploitable zero-day vulnerabilities across network devices, firmware, embedded systems, and open-source software, including a critical unauthenticated remote code execution vulnerability in common protocols in critical infrastructure networks (CVE-2026-32746).
The model and harness are built exclusively for defensive security teams, helping organizations find and fix their own vulnerabilities or solve other complex challenges before attackers do.
These expert capabilities are more important than ever, as organizations responsible for critical infrastructure, network devices, and sensitive codebases cannot access effective tooling for two reasons:
- Frontier models refuse to engage in critical defensive cyber work due to overzealous guardrails
- Cloud solutions force governments to expose the assets governments need to protect
Hero gives defenders on-premises vulnerability research that delivers frontier-surpassing results with zero data leaving the network.
And behind it is Hercules.
Hercules Cyber-Research Model
Hercules is one of Dream's cybersecurity-specialized models. It was trained with unique domain expertise upon thousands of real vulnerability research trajectories. Since it was built ground-up for governments, the system runs entirely on-prem with no external API calls, so that source code, firmware images, and network configurations are all retained within the organization's control. Finally, its specialized toolchain is built for defensive security tasks, augmented with proprietary components like our RFC Analyzer, presented at Black Hat, and our binary emulation framework for firmware and network device research.
The World's Best Cyber Model According to CyberGym
To measure Hercules and Hero's performance against a public, reproducible standard, we evaluated it on CyberGym Level 1, the leading benchmark for AI-driven vulnerability reproduction, which measures performance on 1,507 tasks across 188 open-source projects.
On this benchmark, Hercules and Hero achieved 96.6% differential validation, placing it as the top performer.
Driving Hero

While Hero is model-agnostic, a vulnerability research system that runs on-premise requires a specialized model that also works on-premise. Hercules is a cybersecurity-specialized model post-trained from GLM-5.2, combining unique domain expertise with frontier training and tooling. Notably, Hercules and Hero's scores represent a dramatic improvement upon the base model's initial performance on the CyberGym benchmark (77%) prior to fine-tuning and the harness.
Training Hercules
To train Hercules, we ran Hero at scale across open-source codebases, binaries, and firmware, generating thousands of real vulnerability research trajectories. We applied rejection sampling and human validation to select only high-quality examples of correct reasoning chains, successful exploit constructions, productive tool use, and accurate crash analysis.
Combined with other proprietary tactics, the model can understand constraint chains, format construction, sanitizer output interpretation, and path reachability natively without needing to be taught through prompting alone.
Hercules runs in fp8 precision on local NVIDIA infrastructure and is optimized for the long-horizon agentic workflows that vulnerability research demands. Since no API calls leave the network, the platform is available to run against an organization's own infrastructure without any data exposure.
The Results: 1,000+ Zero-Day Vulnerabilities
Unlike other cyber-defense research projects, Hero and Hercules are live tools that are actively being used by governments around the world.
We securely pointed Hero at some of the most widely deployed network services, firmware, and open-source infrastructure, including targets that have been fuzzed, audited, and hardened for years. Across these engagements, Hero autonomously discovered and validated well over 1,000 previously unknown vulnerabilities. Each finding was confirmed end-to-end with a working exploit produced by the system, not a static suspicion.
The discoveries span critical vulnerability classes across protocol daemons, SCADA systems, embedded firmware, and open-source libraries. Notable findings include:
- CVE-2026-32746 — Pre-authentication RCE in GNU InetUtils telnetd, affecting all versions through 2.7 (Debian, Ubuntu, SUSE, embedded devices)
- CVE-2026-3238 & CVE-2026-3012 — Vulnerabilities in Samba, a cornerstone of enterprise file sharing and Active Directory integration
- CVE-2026-0834 — Authentication bypass in TP-Link Archer C20, Archer AX53, and TL-WR841N routers, enabling unauthenticated administrative command execution including factory reset
- CVE-2026-8602 through CVE-2026-8605 — An unauthenticated RCE chain in ScadaBR, an operational SCADA platform deployed in critical manufacturing, energy, and water systems
- CVE-2026-48916 & CVE-2026-48917 — RCE via unvalidated LDAP referrals in the Jenkins LDAP Plugin
CyberGym PASS@1 results
When benchmarked on CyberGym, the Hercules model and Hero harness combined scores a leading 96.6%, the highest score ever recorded on the Berkeley benchmark.
For this benchmark, Hero operates a focused reproduction pipeline, with static analysis, GDB probing, LLM-guided fuzzing, and PoC construction.
But this only tells part of the story. Combined with Hero, Hercules is designed for full-scope vulnerability research, discovering zero-days across network devices, firmware, protocol implementations, and large codebases using its complete arsenal of 40+ tools.
CyberGym tasks benchmark a more limited mission, focusing on a single named vulnerability, one harness, source code provided. There is no need for live host assessment, binary emulation, RFC protocol analysis, firmware extraction, or network service probing.
While Hercules excels at the CyberGym benchmarking, its accomplishments are actually more impressive taken into account what the benchmark doesn't assess. Specifically:
- CyberGym assumes open access to binaries while Hero enables reverse engineering of closed source packages
- Hero provides full, end-to-end remediation instead of only identifying vulnerabilities. Vulnerability detection is only one subset of the broader Hero capabilities.
- Serving the most sensitive government institutions, Hero is able to run fully sovereign and on-premise, rather than leveraging cloud environments.

How Hero Works
Hercules is combined with Hero, a harness with a pipeline of scoped AI agents that runs deterministically over 40+ proprietary security research tools. Code handles the phase transitions, retries, and artifact routing while the model reasons inside narrow tasks with a clear definition of done. A planner breaks research into a phased task graph, an explorer maps entry points, trust boundaries, and data flow paths, and then multiple worker agents hunt in parallel from different angles, tracing the call chain from entry point to crash site, working out the branch conditions that gate each step, figuring out which input bytes control the path.
Every finding then hits an independent review gate that checks for a concrete path from attacker-controlled input to the vulnerable function, realistic triggering conditions, a real security boundary violation, and novelty. Findings that pass these filters get a dedicated execution environment and a working PoC that triggers the bug dynamically.
The Hero toolchain is purpose-built for this and includes tools like:
- RFC Protocol Vulnerability Analyzer
- Code Property Graph engine
- Binary emulation
- Reverse engineering suite
- Research knowledge base
Conclusion
National security defense today must adapt to a fast-changing reality. AI-based defensive systems that span cyber threat intelligence, posture management and threat detection are mission critical, but cyber-defense has always required a combination of deterministic defensive measures combined with deep human expertise for assessing and defending against emerging threats that break the pattern.
Humans cannot be scaled with data centers and compute. But they can and must be supported as cyber-defense enters the age of the infinite attacker.
Hero and Hercules do just that, with purpose-built security tooling that includes protocol analyzers, code property graphs, binary emulation, format knowledge, and structured validation, to augment the best human researchers with the best AI cyber research bench. With Hero's frontier-competitive results on-premises, defenders no longer need to choose between capability and data sovereignty, keeping modern national stacks more protected than ever.