Corma raises $60M to build defensive cybersecurity AI as AI-powered attacks surge
AI models are getting frighteningly good at attacking computer systems. Defending those same systems is proving much harder.
That widening gap is the problem Corma wants to solve. The cybersecurity AI startup has raised $60 million in seed funding led by Sequoia Capital, with participation from Khosla Ventures and Coatue. Corma is building a foundation model purpose-built for defensive cybersecurity, betting that general-purpose AI models trained heavily on code are poorly equipped for the messy reality of defending large corporate networks.
Corma says its own experiments illustrate the problem. The company built enterprise environments modeled after Fortune 500 organizations and ran hundreds of simulations using leading AI models, including OpenAI’s GPT and Anthropic’s Claude.
The models were first asked to act as attackers and establish persistent threats inside the simulated environments. Researchers then flipped the assignment and asked the same models to find and remove the threats they had created.
The gap was striking: AI attackers succeeded 88% of the time. AI defenders detected just 12% of the threats.
That asymmetry could become one of cybersecurity’s defining problems as autonomous AI agents become more capable.
Modern foundation models have made huge gains in coding, software reasoning, and multi-step tool use. Those skills translate surprisingly well to offensive cybersecurity. Finding vulnerabilities, writing exploit code, and chaining actions against a defined target can resemble the software tasks these models already perform well.
Defense presents a different challenge. Security teams may need to sift through enormous quantities of logs, network traffic, alerts and events, connect seemingly unrelated signals across days or weeks, and make thousands of consistent decisions without losing context.
Corma believes that requires a model built differently from the start.
“The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start,” said Alon Pluda, Co-founder and CEO of Corma. “AI-powered attacks are operating at a speed and sophistication that neither human teams, better tooling, nor general-purpose AI can match. It requires a complete AI-powered defensive workforce, built from the ground up for cybersecurity, that gives defenders the same speed, sophistication, and generalization that AI has already given attackers. Corma’s mission is to make sure the defenders win this race – and every challenge that comes next.”
With $60 Million in Funding, Corma Aims to Build an AI Workforce for Cyber Defense as AI Attackers Win 88% of the Time
Corma’s foundation model serves as the intelligence behind AI agents that can work across different defensive security functions. Rather than positioning the software as another security dashboard, the startup wants organizations to deploy its agents more like digital members of a security team.
The company says early deployments are already running inside Fortune 100 and Fortune 500 organizations spanning healthcare, finance, energy, critical infrastructure and retail.
Corma claims those deployments have cut threat response times by more than 94%, increased coverage across security functions by 15 times and identified multi-stage attacks that might otherwise have gone unnoticed. Those figures come from Corma and will need to be tested against broader deployments as the company scales.
The six-week-old startup has assembled researchers from Google and DeepMind alongside cybersecurity specialists with backgrounds in Israel’s Unit 8200 and major security companies.
“Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs,” said Shaun Maguire, Partner at Sequoia. “Agentic AI gives attackers a structural speed advantage, but Alon’s hacking talent paired with Corma’s frontier AI research helps companies combat these threats at scale.”
The timing helps explain why investors are putting $60 million behind such a young company. AI is lowering the cost of automating tasks that once required skilled hackers, potentially allowing attackers to operate across far more targets simultaneously.
The defensive side may have to become equally autonomous.
That makes Corma’s bigger experiment worth watching. The cybersecurity industry has spent years adding AI features to existing products. Corma is making a more ambitious bet: that defending organizations against AI agents will eventually require AI agents built expressly to fight them.

