2 Sources
[1]
Exclusive: Corma raises $60M from Sequoia, Khosla Ventures for AI trained to defend against cyberattacks | Fortune
The growing number of powerful, widely available AI models has ushered in a dangerous era for cybersecurity. Nefarious actors now have the ability to carry out complex attacks at unprecedented scale, creating a need for more tools to defend against them. That's where Corma comes in, a startup emerging from stealth today with $60 million in seed funding to build AI models for defensive cybersecurity, led by Sequoia Capital, along with Khosla Ventures and Coatue. The announcement did not include Corma's total valuation. Founded in 2025, Corma is based in Tel Aviv and San Francisco. It deployed its first model six weeks ago to a variety of Fortune 100 and Fortune 500 organizations across sectors, including healthcare, financial services, energy, critical infrastructure, and retail. The name "Corma" comes from The Lord of the Rings, CEO Alon Pluda tells Fortune. The books are centered around the quest to destroy an all-powerful ring, or "corma" in Elvish. Pluda says his company's product is like that ring, "but this time for the defenders." Most popular AI models today from companies like OpenAI, Anthropic, and Google are trained to carry out cybersecurity attacks, Pluda said, not to defend against them. For example, these models excel at writing and refining code, identifying bugs, and multi-step reasoning. "Those same capabilities map directly to offensive security," Pluda said. In contrast, Corma trains its AI models to specialize in qualities related to defensive cybersecurity, most of which "doesn't have anything to do with coding," Pluda said. Instead, it's more about "looking at logs, audits, [and] finding the needle in a haystack." Also key: maintaining a consistent approach across thousands of actions. "Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs," said Shaun Maguire, Partner at Sequoia. "Agentic AI gives attackers a structural speed advantage, but Alon's hacking talent paired with Corma's frontier AI research helps companies combat these threats at scale." Corma's model has reduced threat response times by 94% in the organizations that have adopted it, the company says. As we've seen in recent months with OpenAI's models attacking Hugging Face, AI cyberattacks are happening at superhuman speed, making it difficult for human-driven processes to stop them. Corma is helping organizations fight AI with AI. "As cyberattacks become more autonomous and scalable, the stakes move beyond data and finances to critical infrastructure, healthcare systems, and essential services where failures can have real-world consequences," said Vinod Khosla, founder of Khosla Ventures. "That is why we need entirely new approaches to cyber defense and teams like Corma pursuing one of the hardest problems in cybersecurity." "Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs," said Shaun Maguire, Partner at Sequoia. "Agentic AI gives attackers a structural speed advantage, but Alon's hacking talent paired with Corma's frontier AI research helps companies combat these threats at scale." Corma will use the $60 million in funding to further scale its AI models by expanding the data and training that power them. The company will also grow its team, with a focus on hiring top talent across defensive security, AI, and research to continue advancing their model.
[2]
Corma, the First Frontier Defensive Cybersecurity AI Lab, Raises $60M as AI Supercharges Attackers
Backed by Sequoia Capital and Khosla Ventures, Corma is building the first foundation model for defensive cybersecurity, closing the growing asymmetry between AI-powered offense and human-led defense. SAN FRANCISCO, August 10, 2026 (Newswire.com) - Corma, the first frontier AI lab for defensive cybersecurity, today announced $60 million in seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue. Already working with Fortune 100 companies, Corma is developing the first foundation model purpose-built for defensive cybersecurity, tackling a rapidly growing challenge the world is only beginning to confront: AI's offensive cybersecurity capabilities are advancing at an extraordinary pace, while its defensive cybersecurity capabilities continue to fall short of protecting organizations in real-world environments. Foundation models such as OpenAI's GPT, Anthropic's Claude, and Google's Gemini have advanced at an extraordinary pace over the past few years, particularly in coding and software reasoning. These systems can now write and refine software, identify and remediate bugs, reason through complex environments, and orchestrate tools across multi-step workflows. Those same capabilities map directly to offensive security. Vulnerability research and exploit development are, at their core, code-reasoning problems executed against bounded targets. When combined with agentic execution, these models move beyond assisting attackers to autonomously carrying out end-to-end attack chains, as demonstrated in Anthropic's Mythos disclosure. But defensive cybersecurity - everything outside of code security - demands a fundamentally different set of capabilities. Rather than code reasoning and generation, it requires digging through massive volumes of security data (such as audit logs, events, and network flows), correlating weak signals over long time horizons, and maintaining extreme consistency across thousands of decisions in sequence. Corma's research shows just that. Using realistic enterprise environments modeled after Fortune 500 organizations, complete with the dozens of security tools typically deployed in large enterprises, Corma ran hundreds of simulations with leading AI models such as OpenAI's GPT and Anthropic's Claude. First, the models were tasked with acting as attackers, planting persistent threats inside enterprise systems. The same models were then asked to defend those environments, locating and remediating the threats they had created. The results were consistent: in nearly every case, the same AI model that executed an end-to-end attack couldn't defend against the very attack it carried out - AI attackers succeeded 88% of the time, while AI defenders detected just 12%. This highlights a growing imbalance with major implications for cybersecurity. "The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start," said Alon Pluda, Co-founder and CEO of Corma. "AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match. It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication, and generalization that AI has already given attackers. Corma's mission is to make sure the defenders win this race - and every challenge that comes next." Corma is building the first foundation model purpose-built for defensive cybersecurity. It powers Corma's AI agents, allowing them to outperform agents built on other models while generalizing across the full spectrum of defensive security tasks. Organizations onboard Corma much like they would a new team member. Once deployed, Corma's agents can operate across virtually every area of defensive cybersecurity, continuously learn the environment around them, and scale to meet demands that no team could cover alone. Since launching just six weeks ago, Corma's AI workforce has been deployed at Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, critical infrastructure, retail, and other sectors. Early deployments have reduced threat response times by more than 94%, expanded security coverage by 15 times across different security functions, and uncovered multi-stage attack campaigns that would have otherwise gone undetected. "Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs," said Shaun Maguire, Partner at Sequoia. "Agentic AI gives attackers a structural speed advantage, but Alon's hacking talent paired with Corma's frontier AI research helps companies combat these threats at scale." "AI is reshaping cybersecurity in ways that increasingly extend beyond the enterprise to national security and geopolitical stability," said Vinod Khosla, founder of Khosla Ventures. "As cyberattacks become more autonomous and scalable, the stakes move beyond data and finances to critical infrastructure, healthcare systems, and essential services where failures can have real-world consequences. That is why we need entirely new approaches to cyber defense and teams like Corma pursuing one of the hardest problems in cybersecurity." Corma brings together a first-of-its-kind combination of expertise across pre-training, post-training, offensive and defensive cybersecurity - uniting frontier AI researchers from Google and DeepMind with cybersecurity experts from the most elite groups within Israel's 8200 Unit and the world's leading cybersecurity companies. It is the type of interdisciplinary team required to tackle Corma's mission, long considered "the holy grail of cybersecurity." About Corma Corma is the first frontier AI lab for defensive cybersecurity. The company is building the first foundation model purpose-built for defensive cybersecurity, powering a new kind of AI native defensive workforce that gives security teams the same speed, sophistication, and generalization that AI has already given attackers. In a world where AI-powered attacks are advancing at unprecedented speed, Corma's mission is to make sure the defenders win the race - and every challenge that comes next. Founded in 2025 and headquartered in Tel Aviv and San Francisco, Corma is backed by Sequoia Capital, Khosla Ventures, and Coatue."
Share
Copy Link
Corma, a Tel Aviv and San Francisco-based startup, emerges from stealth with $60M seed funding led by Sequoia Capital and Khosla Ventures to build the first foundation model for defensive cybersecurity. Already deployed at Fortune 100 and Fortune 500 companies, Corma's AI agents have reduced threat response times by 94% and expanded security coverage by 15 times across healthcare, financial services, energy, and critical infrastructure sectors.

Corma, a frontier AI lab focused on defensive cybersecurity, has emerged from stealth with $60M seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue
1
2
. Founded in 2025 and based in Tel Aviv and San Francisco, the startup is building AI models trained to defend against cyberattacks at a time when AI-driven cyberattacks are accelerating beyond human capacity to respond. The company deployed its first model just six weeks ago to Fortune 100 and Fortune 500 companies across healthcare, financial services, energy, critical infrastructure, and retail sectors1
.The growing availability of powerful AI models has created a dangerous asymmetry in cybersecurity. Foundation model capabilities from companies like OpenAI, Anthropic, and Google excel at writing code, identifying bugs, and multi-step reasoning—capabilities that map directly to offensive capabilities
1
. Corma's research demonstrates this imbalance starkly. In hundreds of simulations using realistic enterprise environments modeled after Fortune 500 organizations, leading AI models acting as attackers succeeded 88% of the time, while the same models acting as defenders detected threats just 12% of the time2
. This growing gap highlights why organizations need entirely new approaches to combat cyber threats.Unlike general-purpose AI models that prioritize code generation, Corma trains its AI models to specialize in defensive cybersecurity tasks that require different capabilities. CEO Alon Pluda explains that defensive work focuses on "looking at logs, audits, and finding the needle in a haystack" while maintaining consistency across thousands of actions
1
. Corma's foundation model powers AI agents that operate across virtually every area of defensive security, continuously learning their environment and scaling to meet demands no human team could cover alone2
. Organizations onboard Corma much like they would a new team member, integrating it into their existing security infrastructure.Since launching six weeks ago, Corma has already demonstrated significant impact. The company's AI agents have reduced threat response times by more than 94% at deployed organizations, addressing the reality that AI cyberattacks now happen at superhuman speed
1
2
. Beyond speed improvements, early deployments have expanded security coverage by 15 times across different security functions and uncovered multi-stage attack campaigns that would have otherwise gone undetected2
. These results validate Corma's approach of fighting AI with AI, giving defenders the same speed and sophistication that AI has already given attackers.Related Stories
"Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs," said Shaun Maguire, Partner at Sequoia Capital. "Agentic AI gives attackers a structural speed advantage, but Alon's hacking talent paired with Corma's frontier AI research helps companies combat these threats at scale"
1
. Vinod Khosla, founder of Khosla Ventures, emphasized the broader implications: "As cyberattacks become more autonomous and scalable, the stakes move beyond data and finances to critical infrastructure, healthcare systems, and essential services where failures can have real-world consequences"1
. The announcement did not disclose Corma's total valuation.Corma will deploy the $60M seed funding to further scale its AI models by expanding the data and training that power them
1
. The company plans to grow its team with a focus on hiring top talent across defensive security, AI, and research to continue advancing their model. As AI continues reshaping cybersecurity with implications extending to national security and geopolitical stability, watch for how Corma's approach influences the broader market for AI agents in enterprise security. The race to general intelligence in cybersecurity has begun, and Corma is positioning itself to ensure defenders win that race. Organizations should monitor whether this foundation model approach becomes the standard for defensive cybersecurity, potentially reshaping how enterprises staff and structure their security operations in an era of autonomous attacks.Summarized by
Navi
08 Jan 2026•Startups

23 Apr 2025•Technology

10 Jun 2026•Startups

1
Technology

2
Science and Research

3
Policy and Regulation
