Corma raises $60 million as AI gives cyberattackers a growing edge

Sequoia-led round backs Corma’s push to build a foundation model for cyber defense as AI-powered attacks grow faster, more autonomous and harder for traditional security teams to stop

Israeli-American cybersecurity startup Corma has raised $60 million in seed funding as it seeks to build a foundation model designed specifically for cyber defense, the company announced.
The round was led by Sequoia Capital, with participation from Khosla Ventures and Coatue. Corma, founded in 2025 and headquartered in Tel Aviv and San Francisco, says its technology is already being used by Fortune 100 and Fortune 500 companies in sectors including health care, financial services, energy, critical infrastructure and retail.
Corma team
Corma team
Corma team
(Photo: Avishag Shaar-Yashuv)
The company is developing what it describes as the first foundation model purpose-built for defensive cybersecurity, amid growing concern that advances in artificial intelligence are giving attackers capabilities that existing defensive systems struggle to match.
General-purpose AI models such as OpenAI’s GPT, Anthropic’s Claude and Google’s Gemini have improved rapidly in coding and software reasoning, enabling them to write and refine software, identify bugs, reason across complex environments and use tools in multi-step processes.
Those capabilities can also be applied to offensive cybersecurity, where vulnerability research and exploit development rely heavily on code analysis. Combined with autonomous AI agents, such systems can potentially execute more complex attack sequences with less human involvement.
Corma argues that cyber defense presents a different technical challenge. Instead of focusing primarily on code generation and reasoning, defensive systems must process vast quantities of security information, including audit logs, events and network traffic, while identifying weak signals over long periods and maintaining consistency across large numbers of decisions.
In research conducted by the company using simulated enterprise environments modeled on Fortune 500 organizations, Corma tested leading AI models in both offensive and defensive roles. According to the company, the models were first asked to act as attackers and establish persistent threats inside the simulated systems, then tasked with identifying and removing those same threats.
Corma said the AI models successfully carried out attacks in 88% of the simulations, while detecting threats when acting as defenders in only 12% of cases. The findings have not been independently verified.
“The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start,” Corma co-founder and CEO Alon Pluda said.
Pluda said existing human security teams, conventional cybersecurity tools and general-purpose AI systems are struggling to match the speed and sophistication of AI-enabled attacks. Corma’s goal, he said, is to build an AI-based defensive workforce capable of operating at a similar pace and scale.
The company’s foundation model powers AI agents designed to work across a range of defensive cybersecurity functions. Corma says organizations can deploy the agents in a manner similar to adding members to a security team, with the systems learning the organization’s environment and operating across multiple security functions.
Corma said that since launching six weeks ago, its systems have reduced threat response times by more than 94% in early deployments and expanded security coverage by as much as 15-fold across different functions. The company also said its technology identified multi-stage attacks that otherwise would have gone undetected. Those performance figures were provided by Corma and have not been independently confirmed.
Shaun Maguire, a partner at Sequoia Capital, said AI agents are giving cyberattackers a structural advantage in speed and argued that Corma’s combination of AI research and cybersecurity expertise could help companies defend against such threats at scale.
Vinod Khosla, founder of Khosla Ventures, said advances in autonomous cyberattacks could have implications extending beyond individual companies to critical infrastructure, health care and national security.
Corma’s team includes AI researchers with experience at Google and DeepMind as well as cybersecurity specialists from Israel’s Unit 8200 and major cybersecurity companies.
The company says it is combining expertise in AI model training with both offensive and defensive cybersecurity research as it works toward a system capable of handling a broad range of security tasks.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""