Ethical Hacking News
Stopping a cyberattack while walking your dog is not just a metaphor for Corma's AI security startup. The company is on a mission to close the "defense gap" in the cybersecurity landscape, providing organizations with the tools they need to stay ahead of emerging threats. With its commitment to agentic defenders and defensive security, Corma is revolutionizing the way organizations approach cybersecurity.
Corma, a cutting-edge AI security startup, aims to close the "defense gap" in the cybersecurity landscape. Corma's approach is built around the concept of "defensive security" that involves reading logs, events, and configurations to prevent cyberattacks. The company's AI workforce is powered by Corma's models and can be deployed like "team members" to perform various defensive security tasks. Corma's research has shown a significant gap between offensive and defensive security, which the company is working to close. The company's models have shown impressive capabilities in finding and fixing bugs and orchestrating tools across multi-step workflows. Corma's models have limitations, including a high failure rate in detecting attacks, but the company remains optimistic about their potential. Corma has seen significant success in deploying its AI workforce across various environments, resulting in reduced threat response times and expanded security coverage. Corma's goal is to provide organizations with the tools they need to stay ahead of emerging threats and protect their sensitive data.
In a world where cybersecurity threats are becoming increasingly sophisticated, a new player has emerged to challenge the status quo. Corma, a cutting-edge AI security startup, is on a mission to close the "defense gap" in the cybersecurity landscape. According to Corma CEO Alon Pluda, the company aims to create a "one ring to rule them all, for the defenders to have this power." This ambitious goal is rooted in the concept of agentic defenders, which Pluda believes can revolutionize the way organizations approach cybersecurity.
Pluda's inspiration for this mission came from a story about a security executive who was walking his dog when he received a notification on his watch from a Corma agent. The agent had caught a live attack and needed permission to block it. The security executive approved the action, and the agent successfully mitigated the intrusion in under 10 minutes. This anecdote illustrates the potential of agentic defenders to provide real-time protection against cyberattacks.
Corma's approach to cybersecurity is built around the concept of "defensive security," which involves reading logs, events, configurations, audit trails, and on-disk state. This type of security is often overlooked in favor of more proactive measures, such as threat hunting and vulnerability scanning. However, Pluda believes that defensive security is essential to preventing cyberattacks and protecting sensitive data.
The company's AI workforce, powered by Corma's models, can be deployed like "team members" who operate across various defensive security tasks. These models are trained on a range of tasks, including finding and fixing bugs, orchestrating tools across multi-step workflows, and carrying out defensive security tasks that don't involve scanning code for vulnerabilities and misconfigurations.
Corma's research has shown that the gap between offensive and defensive security is significant. While models excel at finding vulnerabilities and exploiting weaknesses, they struggle to detect and mitigate attacks. According to Pluda, this gap is due to the data these models are trained on and the objectives they are trained against, which lend themselves to offensive security.
To close this gap, Corma is working with Fortune 100 companies and training models to achieve "superintelligence for defensive cybersecurity." The company's models are powered by some of the most advanced AI technologies, including those from OpenAI, Anthropic, and Google. These models have shown impressive capabilities in finding and fixing bugs, as well as orchestrating tools across multi-step workflows.
However, Corma's models have also been shown to have limitations. In a recent experiment, the company tested four frontier models against each other in every attacker and defender pairing, including each model against itself. The results showed that the models successfully implanted a persistent backdoor in 85 percent of their runs. However, these same models only detected 19 percent of attacks.
Despite these limitations, Pluda remains optimistic about the potential of Corma's models. He believes that with continued development and refinement, the company's models can become the go-to solution for defensive cybersecurity. Corma's commitment to closing the defensive gap is rooted in its desire to provide organizations with the tools they need to stay ahead of emerging threats.
In recent months, Corma has seen significant success in deploying its AI workforce across various environments. The company has reported that Fortune 100 and 500 organizations across healthcare, financial services, energy, critical infrastructure, retail, and other sectors have deployed Corma's AI workforce. These deployments have resulted in reduced threat response times by more than 94 percent, expanded security coverage by 15 times across different security functions, and uncovered multi-stage attack campaigns.
Pluda's vision for Corma is one of a "one ring to rule them all, for the defenders to have this power." This vision is rooted in the idea that with the right tools and technologies, organizations can stay ahead of emerging threats and protect their sensitive data. Corma's commitment to closing the defensive gap is a testament to its dedication to this mission.
In a world where cybersecurity threats are becoming increasingly sophisticated, Corma's quest to close the defensive gap is a welcome addition to the cybersecurity landscape. By providing organizations with the tools they need to stay ahead of emerging threats, Corma is helping to create a safer, more secure digital world.
Related Information:
https://www.ethicalhackingnews.com/articles/Stopping-a-Cyberattack-while-Walking-Your-Dog-Corma-CEO-Alon-Pludas-Quest-to-Close-the-Defensive-Gap-ehn.shtml
https://www.theregister.com/security/2026/08/16/stopping-a-cyberattack-while-walking-your-dog-defensive-ai-security-ceo-says-its-not-ruff-to-do/5288126
Published: Sun Aug 16 06:11:18 2026 by llama3.2 3B Q4_K_M