Corma raises $60M seed to build AI defense against AI attacks
Israeli startup trains foundation models exclusively for cybersecurity defense after tests show general AI models succeed as attackers 88% of the time but detect threats only 12%.
Israeli startup targets AI asymmetry in cybersecurity
Corma, a Tel Aviv and San Francisco-based startup, has raised $60 million in seed funding to build foundation models designed exclusively for defensive cybersecurity. Sequoia Capital led the round, with participation from Khosla Ventures and Coatue.
The company, founded in 2025, is addressing what it characterizes as a fundamental imbalance: general-purpose AI models have become increasingly capable of executing sophisticated cyberattacks, but remain poorly equipped to defend against them.
CEO and co-founder Alon Pluda told Calcalist that Corma trains language models specifically for defensive cyber operations rather than adapting general-purpose models. The company deploys AI agents that operate across an organization's existing security infrastructure, functioning as what Pluda describes as "virtual human resources" that work alongside security teams.
The attacker advantage
Corma's research highlights the scope of the problem. In hundreds of simulations using realistic enterprise environments modeled on Fortune 500 companies, the startup tested leading AI models including OpenAI's GPT and Anthropic's Claude in both offensive and defensive roles.
The models were first instructed to act as attackers and plant persistent threats. The same models were then tasked with defending the environments and identifying the threats they had created. AI attackers succeeded in 88% of simulations, while AI defenders detected only 12% of the threats.
The disparity stems from different capability requirements. Offensive operations benefit directly from AI's coding and reasoning abilities—understanding vulnerabilities, writing exploits, and executing multi-step attack chains. Defensive operations require processing massive volumes of security events, identifying weak signals over extended periods, and maintaining consistency across thousands of decisions.
Early deployment results
Corma already works with Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, and critical infrastructure. The company reports that early deployments reduced threat-response times by more than 94%, expanded security coverage by 15 times across different functions, and uncovered multi-stage attack campaigns that would otherwise have remained undetected.
The startup employs 20 people in Tel Aviv and is building its foundation model from scratch rather than fine-tuning existing models. Rather than selling conventional software, Corma provides AI agents that execute security tasks end-to-end across an organization's existing tools.
Why it matters
The cybersecurity industry faces a structural challenge as AI capabilities advance. The same foundation models that power productivity tools can accelerate attack development and execution. Anthropic's recent disclosure of its Mythos AI system demonstrated how autonomous agents could execute complete attack chains. If defensive capabilities don't keep pace, organizations face an expanding window of vulnerability where attackers operate with AI assistance while defenders rely on manual processes. Corma's approach—training models exclusively for defense rather than adapting general-purpose AI—represents a bet that specialization is necessary to close this gap.
Corma's founding team includes AI researchers from Google and DeepMind alongside cybersecurity specialists from Israel's Unit 8200 intelligence division and major security companies. The seed round closed in early 2026, according to details first reported by Calcalist.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call