Skip to main content
CybersecurityHacking

AI Security Startup Corma Targets Defensive Gap with Agent Deployment

Person walking dog looks at smartwatch on their wrist.

"I just caught a live attack. I need your permission to block it," Alon Pluda quoted a Corma agent as telling a customer on his watch while the customer was walking his dog, according to an interview Pluda gave to The Register. The customer approved the action, the agent blocked the malware and the attacker from moving across the company's network, and Corma says the intrusion was mitigated in under 10 minutes.

The dog‑walking alert: a real‑time agentic intervention

Corma's CEO, Alon Pluda, uses a single customer anecdote to illustrate how his startup's AI agents operate in the field. Pluda said the security executive received a watch notification from a Corma agent, approved an automated block, and watched the agent stop the attack while "walking outside with his dog." Pluda described the moment as "one of the most magical moments of his year," and told The Register the mitigation took under 10 minutes.

Corma's mission: closing the "defensive gap"

Pluda founded Corma about a year ago and frames the company's purpose as closing what he calls the "defensive gap" — a divergence in performance between models used for offensive security and those used for defensive tasks. He told The Register that while models from OpenAI, Anthropic, and Google are "amazingly good" at coding and language tasks such as finding and fixing bugs and orchestrating multi‑step workflows, their strengths have made them "incredible vulnerability researchers" and, when paired with agentic capabilities, "end‑to‑end attackers."

Pluda argued the imbalance stems from training data and objectives: offensive goals are often straightforward and checkable, while defensive security requires reading "logs, events, configurations, audit trails, and on‑disk state" — structured machine data that Corma contends is a small share of what general foundation models see in training. Defensive reasoning, he said, is more open‑ended and akin to "finding needles in the haystack."

Controlled head‑to‑head testing of frontier models

To quantify the gap, Corma reported recent testing of four "frontier" models — Claude Opus 4.8, GPT‑5.5, Grok 4.3, and DeepSeek V4 — run as both attackers and defenders against the same simulated enterprise network. In that exercise the attacker’s objective was to plant a persistent backdoor; the defender’s objective was to find and stop it. Corma said it ran every attacker/defender pairing, including model versus itself, with 15 independent engagements per pairing and 241 scored engagements in total.

The result, Corma reports, was a stark imbalance: the models successfully implanted a persistent backdoor in 85 percent of runs, while detecting only 19 percent of attacks. Pluda summarized the finding bluntly: "The general foundation models are getting exponentially better at offensive security, but haven't been able to improve on the same rate on defensive security."

Early deployments, funding, and claimed operational gains

Corma announced $60 million in seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue. Pluda said the startup is working with Fortune 100 companies and has deployed its AI agents across organizations in healthcare, financial services, energy, critical infrastructure, retail, and other sectors.

According to Pluda and Corma, those early deployments have produced sizable operational effects: reduced threat response times by more than 94 percent, expanded security coverage by 15 times across different security functions, and uncovered multi‑stage attack campaigns. Pluda framed the objective as producing "superintelligence for defensive cybersecurity" and likened Corma's ambition to an Elven naming joke: the company name comes from an Elven word for "ring," and Pluda said, "We’re building the one ring to rule them all, but this time for the defenders to have this power."

What this means for technologists, procurement leaders, and adversaries

  • Technologists and security teams: Pluda's test results point to a specific operational shortfall — the models Corma tested were far better at implanting persistent backdoors than detecting them. Teams focused on detection, logging, and audit‑data pipelines may prioritize validation of AI agents on structured machine data and defender‑specific tasks before authorizing automated response.
  • Procurement and enterprise leaders: Corma's claims include dramatic reductions in response time and expanded coverage, and the company says it is already working with Fortune 100 customers; procurement leaders will need to evaluate those claimed metrics in their own environments and weigh trust and governance controls for agentic systems that can act autonomously.
  • Adversaries and threat actors: The testing described underscores an asymmetric moment in which agent‑capable models can be optimized toward offense. Pluda explicitly warned that agentic capabilities can turn language and code models into "end‑to‑end attackers," invoking recent incidents "like we saw with the OpenAI and Hugging Face incident."

Corma's public characterization is clear: the frontier models are improving rapidly at offensive tasks, and defenders must close that gap by building agents and models oriented toward structured machine data and open‑ended defensive reasoning. The company's seed round and early enterprise deployments give it runway to pursue that goal; its head‑to‑head testing lays down a measurable benchmark — 85 percent success for attackers versus 19 percent detection for defenders — against which future progress can be judged.

Original story at The Register