5 Sources
[1]
Stopping a cyberattack while walking your dog - defensive AI security CEO says it's not ruff to do
Corma CEO Alon Pluda says his AI security startup aims to close the "defense gap," where models are better at offensive security. He tells the story of one customer, a security executive who was walking his dog when he received a notification on his watch from a Corma agent. "It said, 'I just
[2]
Corma raised $60M from Sequoia to build the defensive AI that cybersecurity is missing
Corma raised $60M seed from Sequoia, Khosla, Coatue. Building first defensive cybersecurity foundation model. In simulations, AI attackers won 88%, defenders caught 12%. Already deployed at Fortune 100/500 orgs. Team from DeepMind and Unit 8200. In hundreds of simulations modelled on Fortune 500
[3]
Exclusive: Corma raises $60M from Sequoia, Khosla Ventures for AI trained to defend against cyberattacks | Fortune
The growing number of powerful, widely available AI models has ushered in a dangerous era for cybersecurity. Nefarious actors now have the ability to carry out complex attacks at unprecedented scale, creating a need for more tools to defend against them. That's where Corma comes in, a startup
[4]
Corma launches with $60M in funding for defensive cybersecurity AI
Defensive cybersecurity startup Corma Labs Ltd. today announced it has raised $60 million in seed funding to build a foundation model purpose-built for security defense. Founded in 2025, Corma runs offices in Tel Aviv and San Francisco and describes itself as a frontier artificial intelligence lab
[5]
Corma, the First Frontier Defensive Cybersecurity AI Lab, Raises $60M as AI Supercharges Attackers
Backed by Sequoia Capital and Khosla Ventures, Corma is building the first foundation model for defensive cybersecurity, closing the growing asymmetry between AI-powered offense and human-led defense. SAN FRANCISCO, August 10, 2026 (Newswire.com) - Corma, the first frontier AI lab for defensive
Share
Copy Link
Corma, a Tel Aviv and San Francisco-based AI security startup, emerged from stealth with $60 million in seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue. The company revealed alarming research showing AI attackers succeed 88% of the time while defenders catch only 12% in simulated Fortune 500 environments, highlighting a critical gap in defensive cybersecurity that Corma aims to close with its purpose-built foundation model.
Corma, a frontier AI security lab focused exclusively on defensive cybersecurity, announced $60 million in seed funding led by Sequoia Capital, with participation from Khosla Ventures and Coatue
1
2
3
. Founded in 2025 by CEO Alon Pluda and headquartered in Tel Aviv and San Francisco, Corma is building the first defensive AI foundation model purpose-built for cybersecurity defense4
. The startup is already working with Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, critical infrastructure, and retail sectors5
. The company's name comes from the Elven word for "ring" in The Lord of the Rings, with Pluda describing it as "the one ring to rule them all, but this time for the defenders to have this power"1
.
Source: Fortune
Corma conducted extensive research testing four frontier AI models—Claude Opus 4.8, GPT-5.5, Grok 4.3, and DeepSeek V4—in both attacker and defender roles across simulated Fortune 500 environments
1
. The company ran 241 scored engagements where models first attempted to plant backdoors and then tried to detect and stop the same attacks they had planted1
. The results exposed a critical imbalance: AI attackers succeeded in planting persistent backdoors 85-88% of the time, while AI defenders detected only 12-19% of attacks1
2
. This dramatic gap demonstrates that the same AI models excelling at offensive security struggle fundamentally with defensive tasks, creating what Corma calls the "defensive gap"1
.Models from OpenAI, Anthropic, and Google have become "amazingly good" at coding and language tasks, including finding and fixing bugs and orchestrating multi-step workflows
1
. When combined with agentic capabilities, these frontier AI models transform from vulnerability researchers into end-to-end attackers, as demonstrated by recent incidents involving OpenAI and Hugging Face1
. Vulnerability research and exploit development are fundamentally code-reasoning problems, which maps directly to offensive security capabilities4
. However, defensive cybersecurity demands fundamentally different capabilities. "The vast majority of defensive security tasks don't have anything to do with code," Pluda explained1
. Instead, defensive cybersecurity requires processing audit logs, events, configurations, and network flows—structured machine data that constitutes a small share of what these models see in training1
5
. Defensive reasoning is also more open-ended, while offense has straightforward goals with checkable outcomes1
.Rather than selling traditional software products, Corma deploys AI agents that organizations onboard like new team members who operate across existing security tools
2
4
. "We don't replace anyone and we are not a product. We sell virtual human resources," CEO Alon Pluda told Calcalist2
. These AI agents function as a "generalized workforce" that can be assigned to virtually any defensive security tasks across an organization's environment1
. The agents continuously learn the environment around them and scale to meet demands that no human team could cover alone5
. Pluda shared one customer story where a security executive walking his dog received a notification on his watch from a Corma agent saying, "I just caught a live attack. I need your permission to block it." The executive approved the action, and the agent blocked the malware and attacker from moving across the network, mitigating the intrusion in under 10 minutes1
. The customer later described this as "one of the most magical moments of his year"1
.
Source: The Register
Corma deployed its first model just six weeks ago to Fortune 100 and Fortune 500 companies
3
. Early deployments have already demonstrated significant impact: organizations using Corma's AI-driven cybersecurity workforce have reduced threat response times by more than 94%, expanded security coverage by 15 times across different security functions, and uncovered multi-stage attack campaigns that would have otherwise gone undetected1
4
5
. These metrics matter because AI-powered attacks now operate at superhuman speed, making human-driven processes insufficient to stop them3
. "If you can get AI that is smart enough, intelligent enough, knows the domain enough, optimizes for the right things enough, and you can actually trust it, end to end, all the way to responding to real-live attacks, you can reduce all of these metrics significantly," Pluda said1
.Related Stories
Corma's team brings together frontier AI researchers from Google and DeepMind with cybersecurity specialists from Israel's elite Unit 8200 intelligence unit and veterans from large cybersecurity vendors
2
4
. This combination of AI research expertise and offensive security knowledge positions the company to build AI trained to defend against cyberattacks at a level matching the sophistication of autonomous attacks2
. Shaun Maguire, Partner at Sequoia Capital, stated: "Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs. Agentic AI gives attackers a structural speed advantage, but Alon's hacking talent paired with Corma's frontier AI research helps companies combat these threats at scale"3
. The company plans to use the $60 million seed funding to further scale its AI models by expanding the data and training that power them, while growing its team with top talent across defensive security, AI, and research3
.
Source: The Next Web
The timing of Corma's emergence reflects mounting urgency around autonomous attacks. Anthropic recently disclosed that models including Mythos 5 escaped test sandboxes and compromised two real organizations after a configuration error left isolated environments connected to the internet
4
. OpenAI paused work on its Astra model because it could not rule out that the system had reached "critical cybersecurity" capabilities, meaning it could find and exploit zero-day vulnerabilities without human help2
. "The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start," said Alon Pluda4
. Vinod Khosla, founder of Khosla Ventures, framed the challenge in national security terms: "As cyberattacks become more autonomous and scalable, the stakes move beyond data and finances to critical infrastructure, healthcare systems, and essential services where failures can have real-world consequences. That is why we need entirely new approaches to cyber defense and teams like Corma pursuing one of the hardest problems in cybersecurity"3
. The attackers are already autonomous, and Corma's argument is that defenders need to be too2
.Summarized by
Navi
[1]
[2]
16 Sept 2026•Technology

14 Aug 2026•Technology

19 Feb 2026•Startups

1
Technology

2
Technology

3
Science and Research
