Corma Emerges From Stealth With $60M Seed to Build Defensive AI for Cybersecurity
Sequoia-led $60M seed round backs Corma's foundation model for autonomous defensive cybersecurity agents, as AI-powered attacks surge.
On August 10, 2026, Corma emerged from stealth mode with a resounding statement of intent: a $60 million seed funding round led by Sequoia Capital, with participation from Khosla Ventures and Coatue. The Tel Aviv- and San Francisco-based startup is building what it calls the first foundation model purpose-built for defensive cybersecurity — a bet that the same generative AI capabilities empowering attackers can, if properly trained and deployed, become the most effective shield against them.
The Threat Landscape: Offense Is Pulling Ahead
The timing of Corma’s debut is no accident. Throughout 2026, the cybersecurity community has watched AI dramatically tilt the balance toward attackers. Leading AI models, when tested as offensive agents in controlled simulations, succeeded in establishing persistent threats in roughly 88% of scenarios. That figure — reported as Corma emerged from stealth — underscores how autonomous agents can now chain together reconnaissance, exploitation, and persistence steps with minimal human intervention.
Industry surveys paint an equally grim picture. According to research cited by Darktrace and others, 87% of security professionals report seeing more AI-driven threats than ever before, and a similar share agree that AI is significantly increasing both the sophistication and success rate of attacks. Agentic AI — autonomous systems that scan networks, craft adaptive phishing campaigns, and execute multi-stage intrusions without human oversight — has become the number-one attack vector of 2026 according to multiple threat intelligence reports. The average cost of an AI-agent-related breach has climbed to $4.7 million, and 92% of organizations describe themselves as concerned about the phenomenon.
The defensive side, by contrast, remains chronically understaffed and reliant on tools that were not designed for machine-speed attacks. Security operations centers (SOCs) drown in alert noise, triage is slow, and the global cybersecurity workforce gap still numbers in the millions. This asymmetry — offense that scales effortlessly against defense that scales with headcount — is precisely the gap Corma was founded to close.
What Corma Is Building
At the core of Corma’s platform is a foundation model trained strictly on security-relevant data: security logs, network audit trails, and operational anomaly detection signals. Unlike general-purpose large language models that have been fine-tuned with a sprinkle of security documentation, Corma’s model was purpose-built from the ground up to reason about threats, understand attacker behavior, and take defensive action.
CEO and co-founder Alon Pluda — an alum of Israel’s elite Unit 8200 intelligence corps — framed the company’s mission in stark terms: Corma is “building foundation models toward superintelligence for defensive cybersecurity.” The deliberate echo of the AGI rhetoric favored by frontier labs signals ambition. Rather than building another copilot that suggests responses to a human analyst, Corma envisions autonomous agents that operate as full members of a security team.
The foundation model powers a set of AI agents that organizations can deploy across their security environment. Once onboarded — the company describes the process as akin to hiring a new team member — these agents work across multiple defensive functions: monitoring, triage, investigation, containment, and remediation. They ingest telemetry from existing security infrastructure, correlate signals across domains that human analysts rarely have time to bridge, and respond to threats at machine speed.
Early Results: 94% Faster Response, 15× Coverage
Corma’s earliest enterprise deployments provide the most compelling evidence that the approach works. According to the company, Fortune 100 and Fortune 500 customers that deployed Corma’s agents during the stealth period cut threat response times by more than 94% and expanded their effective security coverage by a factor of 15.
Those are headline-grabbing numbers, and they demand scrutiny. A 94% reduction in response time could mean the difference between containing a ransomware intrusion in seconds versus hours — the window during which lateral movement and data exfiltration typically occur. A 15× expansion in coverage suggests that Corma’s agents are monitoring systems, threat vectors, or telemetry streams that were previously unwatched, effectively extending the SOC’s reach far beyond what a human team could track.
The company attributes this performance to the depth and specificity of its training data. By focusing exclusively on security logs, network audits, and operational anomalies, Corma’s model avoids the dilution that affects generalist models and develops sharper intuition for what constitutes genuine malicious activity versus benign noise.
The Investor Consensus: Sequoia, Khosla, and Coatue
A $60 million seed round is unusually large by any standard, and the investor roster reads like a who’s who of AI and cybersecurity venture capital. Sequoia Capital led the round, with Khosla Ventures and Coatue participating. Sequoia partner Shaun Maguire confirmed the firm’s conviction on social media, noting that Sequoia led the seed after Khosla Ventures — which had backed Corma earlier — identified the opportunity. This kind of syndicate, assembled before a company has publicly demonstrated its product, signals that top-tier investors believe Corma is tackling a problem both urgent enough and large enough to justify the capital.
The defensive cybersecurity market has long attracted significant investment, but foundation-model-first approaches remain rare. Most AI security tools layer machine learning on top of traditional detection engines; Corma’s bet on a native foundation model for defense represents a fundamentally different architecture. If the approach scales, it could redefine how enterprises build and operate security programs.
The Broader Context: AI Versus AI
Corma’s launch crystallizes a broader dynamic that will define cybersecurity for the remainder of the decade: the AI arms race between attackers and defenders. The UK’s AI Security Institute recently demonstrated that frontier AI agents can execute complex cyber operations with alarming effectiveness — and occasionally take unauthorized actions against real targets. Carnegie Endowment researchers have warned that Europe and other regions face a governance gap in addressing autonomous offensive cyber operations. The offensive side is not waiting for permission.
Defenders, meanwhile, have largely been forced to repurpose general-purpose AI tools or rely on narrow, rules-based systems that cannot keep pace with adaptive, agentic threats. Corma’s thesis is that the answer is not better wrappers around existing models but a purpose-built foundation model that understands defense as deeply as offensive agents understand attack. It is a thesis that resonates with investors, early customers, and a security industry desperate for tools that can fight AI with AI.
What Comes Next
Corma plans to use the $60 million to expand its research and engineering teams, deepen its foundation model’s capabilities, and scale deployments beyond its initial Fortune 100/500 cohort. The company faces significant challenges: defensive AI must operate with far lower error tolerance than consumer applications, the regulatory landscape for autonomous security agents is still evolving, and the trust barrier for letting AI take containment actions in production environments is high.
But the alternative — continuing to fight machine-speed attacks with human-speed defenses — is increasingly untenable. As AI-powered intrusions multiply and the cybersecurity workforce gap persists, the demand for autonomous defensive agents will only grow. Corma’s $60 million seed is a down payment on a future where the best defense against an AI attacker is, finally, an AI defender.
Sources
- [1] https://fortune.com/2026/08/10/exclusive-corma-raises-60-million-from-sequoia-for-ai-trained-to-defend-against-cyberattacks/
- [2] https://www.citybiz.co/article/886517/corma-raises-60-million-seed-round-to-build-defensive-cybersecurity-ai/
- [3] https://www.ynetnews.com/business/article/syqhmevifx
- [4] https://aiweekly.co/alerts/corma-raises-60m-seed-from-sequoia-for-defensive-cyber-ai
- [5] https://techstartups.com/2026/08/10/corma-raises-60m-to-build-defensive-cybersecurity-ai-as-ai-powered-attacks-surge/
- [6] https://ventureburn.com/corma-raises-60m-ai-cybersecurity/