Corma raises $60M for defensive cyber AI
The AI-vs-AI security race just got its first dedicated funding play: a fresh lab with Sequoia's backing is betting that defenders need frontier models of their own, not better tools bolted onto the old ones.
Corma, a Tel Aviv- and San Francisco-based startup building foundation models for defensive cybersecurity, emerged from stealth with a $60 million seed round led by Sequoia Capital, with Khosla Ventures and Coatue participating. Founded in 2025 with roughly 20 employees in Tel Aviv, the company says it is already working with Fortune 100 and Fortune 500 organizations across healthcare, financial services, energy, critical infrastructure and retail. Its pitch: general-purpose frontier models have made attackers dramatically more capable — think autonomous, end-to-end attack chains of the kind Anthropic disclosed with its Mythos system — while defenders still run on human-scale tooling. Corma's answer is a model trained specifically for cyber defense, powering AI agents that work across security functions and continuously learn the environment they are deployed in.
The company is making big claims to justify the "frontier lab" label. CEO and co-founder Alon Pluda says the model "has already far surpassed every general-purpose frontier model on defensive cybersecurity tasks," and frames the mission in race terms: "The race to general intelligence in cybersecurity has already begun, and the attackers have a significant head start." Sequoia partner Shaun Maguire, who led the round, puts the asymmetry at the center of the thesis: "Corma has trained its model for the complexity of real-world attacks and is building the intelligence layer defense actually needs."
Why this matters beyond the check size: it is the cleanest signal yet that the industry's answer to AI-powered offense is specialized models, not general ones. Defense is a different problem than offense — security teams must grind through enormous volumes of audit logs, security events and network traffic, spot weak signals that emerge over long periods, and stay consistent across thousands of decisions. That is plausibly a workload where a model trained on cyber data beats a generalist. But "first" labels are cheap in AI, and Corma has published no benchmark evidence to back its surpassing-the-frontier claim.
The round itself is the other story: Sequoia, Khosla and Coatue writing a $60 million seed into a 20-person lab is an unusually large first check even by 2026 standards. That is a bet on the thesis as much as the team — and a sign that the defense gap is now seen as a model problem worth frontier-lab money, not a procurement problem.
What to watch: whether Corma publishes verifiable benchmarks for its "beyond frontier models" claim — and whether the big security vendors answer with specialized models of their own.
If attackers are getting frontier AI, do defenders need their own models — or just better tooling? Tell us in the comments.
Sources: Access Newswire (press release) · Calcalist · Ynet · citybiz · Techmeme