Israeli Startup Corma Raises $60 Million to Turn AI Against Cyberattackers
The Tel Aviv and San Francisco company says its purpose-built model cut threat-response times by more than 94%. Its agents are already deployed at Fortune 100 and Fortune 500 organizations
Jewish Onliner is an independent publication. If you find our work valuable, please consider becoming a paid subscriber. You can also subscribe to us on WhatsApp and Telegram. Follow us on YouTube, TikTok, Instagram, Discord, and X.
Israeli cybersecurity startup Corma emerged from stealth on Aug. 10 with a $60 million seed round led by Sequoia Capital, alongside Khosla Ventures and Coatue, to build artificial intelligence designed specifically for cyber defense.
Founded in 2025 and headquartered in Tel Aviv and San Francisco, Corma says its autonomous agents are already operating inside Fortune 100 and Fortune 500 organizations in healthcare, financial services, energy, critical infrastructure and retail. The company is positioning its technology as an AI security workforce that can work across an organization’s existing tools and carry out defensive tasks from investigation through remediation.
The financing was disclosed in a company announcement and reported by CTech and The Next Web. It is Corma’s first publicly announced funding round.
An AI Workforce for Existing Security Systems
Corma is developing its own foundation model for defensive cybersecurity rather than building an application entirely on top of a general-purpose model. Its agents are designed to analyze audit logs, security events and network traffic, coordinate across existing security products and complete multi-step defensive work.
Co-founder and CEO Alon Pluda told Calcalist that Corma does not aim to replace a company’s security team or its current products. He described the service as “virtual human resources,” with each customer choosing how many AI workers it wants to deploy.
The model powers what the company calls general security employees. According to Sequoia Capital’s account of the investment, the agents can work across security operations, identity management, cloud security and network security.
That approach differs from security software that generates additional alerts for human analysts. Corma says its agents can investigate activity, make decisions across a sequence of steps and act through the tools an organization already uses.
Corma Reports an 88 Percent Offense-Defense Gap
Corma based its product strategy on internal testing that it says exposed a major weakness in general-purpose AI models.
The company ran hundreds of simulations in environments modeled on Fortune 500 networks with dozens of security tools. Leading models, including OpenAI’s GPT and Anthropic’s Claude, were first instructed to act as attackers and install persistent threats. The same models were then tasked with finding and removing the threats they had created.
According to Corma’s published findings, the AI attackers succeeded in 88% of the simulations, while the AI defenders detected only 12% of the threats.
The company attributes the gap to the different demands of offensive and defensive security. Coding, software reasoning and vulnerability research align closely with capabilities already developed by general-purpose models. Defense often requires a model to sift through enormous volumes of logs, connect weak signals over long periods and remain consistent across thousands of sequential decisions.
Early Deployments Target Critical Sectors
Corma says it launched its AI workforce six weeks before the funding announcement and deployed the agents at large enterprises. In those early deployments, the company reports that its technology reduced threat-response times by more than 94% and expanded security coverage across different functions by 15 times.
According to Sequoia Capital, a Corma agent identified, contained and remediated an active attack campaign during its first hour inside a customer’s network. The customer’s security team had reportedly missed the campaign for 52 days. The investor did not identify the company involved, and Corma has not named its customers or disclosed the sample size behind its performance figures.
The focus on healthcare, energy and critical infrastructure gives the company’s work consequences beyond conventional data theft. Khosla Ventures founder Vinod Khosla said increasingly autonomous attacks can affect essential services and national security as well as corporate systems and finances.
Israeli Cyber Expertise Meets Frontier AI Research
Corma’s team combines AI researchers with experience at Google and DeepMind and cybersecurity specialists drawn from Israel’s Unit 8200 and major security companies. Calcalist reported that the company employs 20 people in Tel Aviv.
Pluda previously co-founded application-security company Miggo Security and served as its chief technology officer.
Sequoia partner Shaun Maguire said agentic AI gives attackers “a structural speed advantage.” Corma’s response is to build a specialized defensive model whose agents can operate at machine speed while remaining integrated with human security teams and their existing infrastructure.
Pluda told Calcalist that the seed round closed in early 2026 and that Corma, already working with several large companies, was not rushing to raise additional capital.






