HomeMalware & ThreatsCorma Secures $60 Million to Develop Cyber Defense Foundation Models

Corma Secures $60 Million to Develop Cyber Defense Foundation Models

Published on

spot_img

Corma Highlights the Need for Specialized AI Models in Defensive Cybersecurity

In an evolving landscape of cyber threats, a notable frontier in artificial intelligence (AI) has emerged, targeting defensive cybersecurity. Corma, a San Francisco-based AI lab, recently announced it has secured $60 million in funding to develop domain-specific foundation models designed explicitly for defensive security. This funding round, led by Sequoia Capital, aims to propel the creation of advanced AI systems that can efficiently handle the unique challenges faced by cybersecurity professionals.

Corma was established in September 2025 by Alon Pluda, who has a rich background in military intelligence, specifically in cybersecurity roles within the Israeli Military Intelligence. Pluda emphasized that effective enterprise security relies on fundamentally different data sets and workflows compared to those applicable to offensive security tactics. In his view, there is an ongoing "race between offensive and defensive security," where defenders must bolster their technological capabilities to keep pace with attackers. "Defenders need to have the AI capabilities that will enhance them just as much as the AI currently enhances the attackers," he stated, underscoring the urgent need for faster development in this field.

Corma aims to bridge the gap identified by Pluda. Defensive cybersecurity teams must grapple with vast amounts of data, including network flows, audit logs, configurations, and various telemetry types, in their quest for crucial indicators within this sea of information. The complexity does not end there; these teams must navigate intricate decision pathways, making it clear that general-purpose AI models fall short of the specialized demands of defensive security tasks.

Pluda articulated that general-purpose models are not adequately equipped to tackle the specific needs associated with defensive security. "The vast majority of enterprise defensive security work doesn’t even have to do anything with code," he explained. Instead, much of it revolves around analyzing logs, configurations, and network flows, where finding subtle signals can be the difference between a significant breach and a secured system.

Corma seeks to develop a security model that can effectively execute existing tools, craft queries, analyze dashboards, and manage workflows—all while producing reliable and consistent results. In this context, variability or creativity in AI responses can pose challenges, as organizations often rely on consistent evidence for security decisions. Accordingly, Corma prioritizes "repeatability" in its models. Pluda stressed the importance of achieving consistent outcomes: "If you run it 100 times, you want to get 100 times the same result. All of these things are just examples of things that general foundation models are not optimized for, and our model is optimized for."

To achieve this level of specificity, Corma employs a unique training methodology. During the pre-training phase, the lab exposes its models to data types and knowledge that may be underrepresented in traditional general-purpose models. The post-training phase includes reinforcement learning, allowing the models to adapt across various security tools and scenarios. In addition, Corma leverages adversarial training to simulate real-world environments where models can act in both attacking and defending roles. "By the first time that the model first hits an enterprise, it’s already been trained on millions and millions of different scenarios," Pluda explained, highlighting the model’s readiness for real-world application.

The evaluation processes employed by Corma scrutinize multiple facets of cybersecurity operations: network security, cloud security, and incident response, among others. Accuracy and consistency are paramount, as is the model’s ability to discern true positives from false ones, provide timely responses, and ensure thorough coverage of the operational environment. "We measure it with end-to-end results, accuracy, consistency, the ability to never miss any true positive," Pluda noted.

Corma’s AI model interfaces seamlessly with existing security tools, engaging human analysts through platforms like Microsoft Teams, Slack, and various ticketing systems. This design philosophy aims to bolster human capabilities rather than relegate teams to isolated environments. "The only one thing that we offer for enterprises is end-to-end security workforce, working alongside your human security team," Pluda clarified.

Moreover, Corma allows organizations to start by delegating basic, repetitive tasks to their AI models, gradually extending trust and autonomy as they validate its efficacy. In certain instances, the system can recognize suspicious activities and seek human approval before acting. Other organizations may empower the AI to take immediate actions, such as isolating compromised hosts, based on its proven accuracy and reliability.

As companies like Corma advance the field of cybersecurity, the playing field for protective measures may begin to shift. The development of specialized AI models could redefine how organizations approach their defenses, exemplifying the vital role of technological innovation in counteracting the ever-evolving landscape of cyber threats.

Source link

Latest articles

Hackers Take Advantage of Serious VMware vCenter Vulnerability to Implement Reverse SSH in 47 Countries

Threat researchers have uncovered an active campaign that exploits a critical vulnerability in VMware...

Gunra Ransomware Targets Critical Infrastructure by Exploiting Fortinet Vulnerabilities

Gunra Ransomware Targets Government and Critical Infrastructure: Joint Advisory Issued by US and South...

Researcher Develops Solution for Microsoft Defender Security Patch

Threats Emerge from Vulnerabilities within Antivirus Software In a recent statement, cybersecurity experts have raised...

More like this

Hackers Take Advantage of Serious VMware vCenter Vulnerability to Implement Reverse SSH in 47 Countries

Threat researchers have uncovered an active campaign that exploits a critical vulnerability in VMware...

Gunra Ransomware Targets Critical Infrastructure by Exploiting Fortinet Vulnerabilities

Gunra Ransomware Targets Government and Critical Infrastructure: Joint Advisory Issued by US and South...

Researcher Develops Solution for Microsoft Defender Security Patch

Threats Emerge from Vulnerabilities within Antivirus Software In a recent statement, cybersecurity experts have raised...