TLDRocket
Sign in

Exclusive: Corma raises $60M from Sequoia, Khosla Ventures for AI trained to defend against cyberattacks

Fortune Emily Forlini Covered by 3 sources

Corma just raised $60M to build AI that defends against cyberattacks. Its pitch: if attackers are using AI at speed, defenders need AI built for the job.

Based on reporting by Fortune, Emily Forlini — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Corma has come out of stealth with $60 million in seed funding to build AI models for defensive cybersecurity. The round was led by Sequoia Capital, with Khosla Ventures and Coatue also backing the startup. Corma did not disclose a valuation.

The company was founded in 2025 and is split between Tel Aviv and San Francisco. It says its first model went live six weeks ago and is already being used by a range of Fortune 100 and Fortune 500 organizations in healthcare, financial services, energy, critical infrastructure, and retail.

The bet here is simple: the big AI models everyone talks about are being trained for offense, not defense. Corma’s CEO, Alon Pluda, says systems from OpenAI, Anthropic, and Google are good at code, bug hunting, and multi-step reasoning, which maps neatly onto offensive security. Corma is pushing in the opposite direction, training for the messier side of defense: logs, audits, pattern-spotting, and keeping the same response across thousands of actions.

That pitch is landing with investors. Sequoia’s Shaun Maguire says agentic AI gives attackers a speed advantage, while Vinod Khosla argues that the risk now reaches beyond data and money into healthcare, infrastructure, and other essential services. Corma says its model has cut threat response times by 94% in organizations using it.

The new money will go into bigger models, more training data, and hiring across defensive security, AI, and research. The company’s name comes from The Lord of the Rings, where the point is to destroy the ring. Pluda’s version is built for the people trying to stop it.

My take — AI-written commentary, not fact-checked reporting

This is the right fight to pick. The industry spent years treating security like a side quest while the model builders kept making attackers faster, cheaper, and annoyingly scalable. Defensive AI is where the real product work is now, not in another demo that writes plausible code and calls it safety.

Read more about this at: Fortune

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.