3 Sources
[1]
Broadcom updates VMware security for AI-era threats
Broadcom Inc. today introduced new security, performance and automation capabilities for VMware Cloud Foundation that are intended to help enterprises defend private clouds against artificial intelligence-assisted attacks while reducing operational complexity and infrastructure costs. The updates affect VMware vDefend and VMware Avi Load Balancer. They include a guided process for deploying advanced threat prevention, on-premises malware analysis, support for air-gapped environments and application programming interface protection. Broadcom is also adding AI assistants to both products and automating migrations from legacy firewalls. "As AI-fueled cyberattacks and vulnerability exploits redefine the threat landscape, a fragmented security approach is no longer an option," said Umesh Mahajan, vice president and general manager of Broadcom's application networking and security division, in a statement. The new vDefend 1-2-3 workflow provides a three-stage process for deploying intrusion detection and prevention, network traffic analysis and network detection and response. It first assesses an organization's threat posture, then applies recommended policies to shared infrastructure such as Active Directory and the Domain Name System before extending them across development, production and demilitarized zones. Broadcom said the workflow can reduce deployment times from months to weeks. The company is also bringing malware sandboxing on-premises, allowing enterprises to analyze static and dynamic files without sending them to a public cloud. Air-gapped support permits organizations to download threat-intelligence updates separately and manually transfer them into disconnected environments. The capabilities are intended for organizations subject to strict privacy, sovereignty and regulatory requirements. Broadcom said all vDefend functions can now operate on-premises. Avi Load Balancer gains native API protection for virtual machines, VMware vSphere Kubernetes Service and AI workloads. It combines a web application firewall with API protection to identify exposed interfaces and reduce reliance on separate security products. Broadcom also reported significant performance improvements, based on internal testing conducted in July. It said Distributed Firewall throughput can reach 22 gigabits per second on servers with 25-gigabit network interface cards and 75 gigabits per second on 100-gigabit systems. At the scale of a VMware Cloud Foundation instance, the company claims throughput of up to 75 terabits per second. The distributed intrusion detection and prevention system can now deliver as much as 17 gigabits per second per server and 17 terabits per second per VMware Cloud Foundation instance. Avi Load Balancer throughput has increased to as much as 12.25 terabits per second per controller instance. A new two-node Security Services Platform configuration can reduce physical hardware requirements by up to 33%. AI assistants embedded in vDefend and Avi provide configuration information, troubleshooting help and remediation guidance. The vDefend assistant can also identify duplicate firewall policies and help automate rule cleanup. An updated vDefend and Avi Conversion Tool automates the translation of rules from agent-based firewalls into native vDefend policies. The capabilities are included in vDefend Security Services Platform 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4 and vACT 3.0. All are compatible with VMware Cloud Foundation 9.1.
[2]
Broadcom Enhances Cyber Defense and Efficiency with New vDefend and Avi Updates
New Updates Layer Additional Defenses To VMware Cloud Foundation to Better Secure the Modern Private Cloud in the Frontier AI Era Broadcom Inc. today announced new updates to VMware vDefend and VMware Avi Load Balancer to deliver a rapidly deployed, intelligently operated, and high performance multi-layer cyber defense. These enhancements expand private cloud security capabilities, optimize infrastructure costs, and use AI-powered automation to simplify operations for overextended IT teams. With vDefend and Avi Load Balancer, enterprises can achieve a more cyber-resilient private cloud with VMware Cloud Foundation (VCF) while delivering scale-out workload security, operational efficiency, and rapid roll-out. "As AI-fueled cyberattacks and vulnerability exploits redefine the threat landscape, a fragmented security approach is no longer an option," said Umesh Mahajan, vice president and general manager, Application Networking and Security Division, Broadcom. "With today's updates to vDefend and Avi Load Balancer, we are giving enterprise customers the protection, performance, and automation they need to defend their application infrastructure at scale." Defending Against Frontier AI Threat Landscapes The impact of frontier AI models on IT security demands more than perimeter or point defenses to protect enterprise applications and data. It requires a multi-layer strategy that identifies and blocks threats to private cloud workloads at unprecedented scale and speed. Broadcom is introducing important updates to vDefend and Avi Load Balancer that enhance protection at multiple layers for modern private clouds built on VCF. Enhanced Lateral Security with vDefend Security Services Platform (SSP): * Accelerated Advanced Threat Prevention (ATP) with vDefend 1-2-3: Introduces a streamlined, three-step deployment framework that accelerates time-to-value for ATP, enabling overextended IT teams to rapidly deploy defenses in just a few weeks instead of many months. vDefend now offers the 1-2-3 workflow for ATP in conjunction with Distributed Firewall (DFW). Together, they leverage deep workload-level visibility to highlight security posture, recommend rules, and provide guided workflows to further strengthen security. * On-Prem Malware Prevention: Brings malware sandboxing on-premises, analyzing static and dynamic artifacts entirely within the local network. All vDefend capabilities are now fully supported on prem, enabling enterprises to keep sensitive data in place and maintain control over their security protocols. * Comprehensive Air-Gapped Support: All vDefend capabilities are now fully supported in air-gapped environments. This deployment model enables secure, offline threat intelligence updates so highly sensitive environments can stay current on the latest threat vectors without ever connecting to the cloud. API Protection with Avi Load Balancer: APIs are increasingly exploited by attackers to infiltrate private cloud environments. Broadcom is further enhancing Avi Load Balancer's security capabilities by introducing native API protection for virtual machines (VMs), vSphere Kubernetes Services (VKS), and AI workloads. The combination of Web Application Firewall and API Protection (WAAP) protects vulnerable APIs and gives enterprises comprehensive visibility to close security gaps while reducing the high cost and complexity of multiple disconnected tools. Optimizing Performance to Lower Infrastructure Costs To counter rising server hardware expenses, the latest optimizations to vDefend and Avi Load Balancer help enterprises get more value from their existing infrastructure investment. * Leaner 2-Node SSP Deployment: vDefend introduces a 2-node SSP model that reduces the physical hardware required to run the platform by up to 33%, lowering infrastructure costs while delivering comprehensive lateral segmentation. * Distributed Firewall Performance Boosts: To deliver Zero Trust lateral security to data-heavy AI workloads, vDefend delivers significant throughput gains by driving DFW speeds up to 22Gbps on 25G NIC servers (up to 129% increase) and up to 75Gbps on 100G NIC servers (up to additional 241% increase). This amounts to DFW scale-out performance of up to 75Tbps per VCF instance. * Distributed Intrusion Detection and Prevention System (IDPS) Performance: To combat the rise of frontier AI discovered software vulnerabilities, vDefend IDPS enables distributed virtual patching to block workload-level exploits in the hypervisor itself, buying time to roll out software patches. vDefend can now boost IDPS performance to up to 17Gbps per server (up to 89% increase), delivering up to 17Tbps scale-out performance for distributed virtual patching per VCF instance. * Improved Application Delivery Performance: Avi Load Balancer scale-out throughput is also boosted up to 12.25Tbps (up to 88% increase) per controller instance. Simplifying Deployment and Operations with AI-Powered Tools Broadcom is introducing an AI-powered assistant and advanced migration tool to streamline day-to-day operations and accelerate network migration. By embedding intelligence directly into the infrastructure, these updates can remove operational complexity and speed up the transition from legacy security solutions. * AI Assistant: Both vDefend DFW and Avi Load Balancer now include AI Assistant to better streamline lateral security and load balancing operations. They embed AI-powered automation directly into the platform to simplify troubleshooting and remediation. * Automated Migration to vDefend DFW: The vDefend and Avi Conversion Tool (vACT) enhancement simplifies and automates the migration process of legacy, agent-based firewall solutions to DFW, significantly reducing migration cost and speeding up security posture. These new enhancements are delivered in vDefend SSP 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4, and vACT 3.0 releases, and are compatible with the VCF 9.1 release.
[3]
Broadcom Announces Updates to Vmware Vdefend and Avi Load Balancer
Broadcom Inc. announced new updates to VMware vDefend and VMware Avi Load Balancer to deliver a rapidly deployed, intelligently operated, and high performance multi-layer cyber defense. These enhancements expand private cloud security capabilities, optimize infrastructure costs, and use AI-powered automation to simplify operations for overextended IT teams. With vDefend and Avi Load Balancer, enterprises can achieve a more cyber-resilient private cloud with VMware Cloud Foundation (VCF) while delivering scale-out workload security, operational efficiency, and rapid roll-out. Broadcom is introducing important updates to vDefend and Avi Load Balancer that enhance protection at multiple layers for modern private clouds built on VCF. Accelerated Advanced Threat Prevention (ATP) with vDefend 1-2-3: Introduces a streamlined, three-step deployment framework that accelerates time-to-value for ATP, enabling overextended IT teams to rapidly deploy defenses in just a few weeks instead of many months. vDefend now offers the 1-2-3 workflow for ATP in conjunction with Distributed Firewall (DFW). Together, they leverage deep workload-level visibility to highlight security posture, recommend rules, and provide guided workflows to further strengthen security. On-Prem Malware Prevention: Brings malware sandboxing on-premises, analyzing static and dynamic artifacts entirely within the local network. All vDefend capabilities are now fully supported on prem, enabling enterprises to keep sensitive data in place and maintain control over their security protocols. Comprehensive Air-Gapped Support: All vDefend capabilities are now fully supported in air-gapped environments. This deployment model enables secure, offline threat intelligence updates so highly sensitive environments can stay current on the latest threat vectors without ever connecting to the cloud. Broadcom is further enhancing Avi Load Balancer?s security capabilities by introducing native API protection for virtual machines (VMs), vSphere Kubernetes Services (VKS), and AI workloads. The combination of Web Application Firewall and API Protection (WAAP) protects vulnerable APIs and gives enterprises comprehensive visibility to close security gaps while reducing the high cost and complexity of multiple disconnected tools. vDefend introduces a 2-node SSP model that reduces the physical hardware required to run the platform by up to 33%, lowering infrastructure costs while delivering comprehensive lateral segmentation. To deliver Zero Trust lateral security to data-heavy AI workloads, vDefend delivers significant throughput gains by driving DFW speeds up to 22Gbps on 25G NIC servers (up to 129% increase) and up to 75Gbps on 100G NIC servers (up to additional 241% increase). This amounts to DFW scale-out performance of up to 75Tbps per VCF instance. vDefend IDPS enables distributed virtual patching to block workload-level exploits in the hypervisor itself, buying time to roll out software patches. vDefend can now boost IDPS performance to up to 17Gbps per server (up to 89% increase), delivering up to 17Tbps scale-out performance for distributed virtual patching per VCF instance. Avi Load Balancer scale-out throughput is also boosted up to 12.25Tbps (up to 88% increase) per controller instance. Broadcom is introducing an AI-powered assistant and advanced migration tool to streamline day-to-day operations and accelerate network migration. By embedding intelligence directly into the infrastructure, these updates can remove operational complexity and speed up the transition from legacy security solutions. Both vDefend DFW and Avi Load Balancer now include AI Assistant to better streamline lateral security and load balancing operations. They embed AI-powered automation directly into the platform to simplify troubleshooting and remediation. The vDefend and Avi Conversion Tool (vACT) enhancement simplifies and automates the migration process of legacy, agent-based firewall solutions to DFW, significantly reducing migration cost and speeding up security posture. These new enhancements are delivered in vDefend SSP 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4, and vACT 3.0 releases, and are compatible with the VCF 9.1 release.
Share
Copy Link
Broadcom unveiled major updates to VMware vDefend and Avi Load Balancer, introducing AI-powered automation, on-premises malware prevention, and air-gapped environment support. The enhancements deliver up to 241% throughput gains while reducing hardware requirements by 33%, addressing the surge in AI-assisted cyberattacks targeting private cloud infrastructure.

Broadcom Inc. announced significant updates to VMware vDefend and Avi Load Balancer, delivering multi-layer cyber defense capabilities designed to protect private cloud infrastructure from AI-fueled cyberattacks
1
. The enhancements expand private cloud security capabilities, optimize infrastructure costs, and leverage AI-powered automation to simplify operations for overextended IT teams working with VMware Cloud Foundation2
."As AI-fueled cyberattacks and vulnerability exploits redefine the threat landscape, a fragmented security approach is no longer an option," said Umesh Mahajan, vice president and general manager of Broadcom's application networking and security division
1
. The updates address the growing challenge of frontier AI models that enable attackers to discover vulnerabilities and launch sophisticated attacks at unprecedented scale and speed.The new vDefend 1-2-3 workflow introduces a streamlined, three-step deployment framework that accelerates time-to-value for Advanced Threat Prevention, enabling IT teams to rapidly deploy defenses in just a few weeks instead of many months
2
. The guided process first assesses an organization's threat posture, then applies recommended policies to shared infrastructure such as Active Directory and the Domain Name System before extending them across development, production and demilitarized zones1
.Working in conjunction with distributed firewall capabilities, the workflow leverages deep workload-level visibility to highlight security posture, recommend rules, and provide guided workflows to strengthen lateral security
3
. This approach enables organizations to deploy intrusion detection and prevention, network traffic analysis, and network detection and response capabilities more efficiently.Broadcom is bringing malware sandboxing on-premises, allowing enterprises to analyze static and dynamic artifacts entirely within the local network without sending files to public cloud services
1
. All VMware vDefend capabilities are now fully supported on-premises, enabling enterprises to keep sensitive data in place and maintain control over their security protocols2
.Air-gapped environment support permits organizations to download threat-intelligence updates separately and manually transfer them into disconnected environments
1
. This deployment model enables secure, offline threat intelligence updates so highly sensitive environments can stay current on the latest threat vectors without ever connecting to the cloud3
. These capabilities target organizations subject to strict privacy, sovereignty and regulatory requirements.Avi Load Balancer gains native API protection for virtual machines, vSphere Kubernetes Services, and AI workloads
1
. The combination of Web Application Firewall and API Protection protects vulnerable APIs and gives enterprises comprehensive visibility to close security gaps while reducing the high cost and complexity of multiple disconnected tools2
.APIs are increasingly exploited by attackers to infiltrate private cloud environments, making this enhanced protection critical for organizations running AI workloads
3
. The integrated approach identifies exposed interfaces and reduces reliance on separate security products, streamlining cyber defense operations.Broadcom reported significant performance improvements based on internal testing conducted in July. Distributed firewall throughput can reach 22 gigabits per second on servers with 25-gigabit network interface cards (up to 129% increase) and 75 gigabits per second on 100-gigabit systems (up to 241% increase)
1
. At the scale of a VMware Cloud Foundation instance, the company claims throughput of up to 75 terabits per second2
.The distributed intrusion detection systems can now deliver as much as 17 gigabits per second per server (up to 89% increase) and 17 terabits per second per VCF 9.1 instance
3
. Avi Load Balancer throughput has increased to as much as 12.25 terabits per second per controller instance (up to 88% increase)1
. These throughput gains enable distributed virtual patching to block workload-level exploits in the hypervisor itself, buying time to roll out software patches.Related Stories
A new two-node Security Services Platform configuration can reduce physical hardware requirements by up to 33% while delivering comprehensive lateral segmentation
1
. This leaner deployment model helps enterprises get more value from their existing infrastructure investment and counter rising server hardware expenses2
.The optimizations to VMware vDefend and Avi Load Balancer enable organizations to achieve cyber-resilience while lowering infrastructure costs
3
. Combined with the performance improvements, these updates deliver scale-out workload security and operational efficiency for modern private clouds built on VMware Cloud Foundation.AI assistants embedded in VMware vDefend and Avi Load Balancer provide configuration information, troubleshooting help and remediation guidance
1
. The vDefend assistant can identify duplicate firewall policies and help automate rule cleanup, removing operational complexity from load balancing operations2
.An updated vDefend and Avi Conversion Tool (vACT 3.0) automates the translation of rules from agent-based firewalls into native vDefend policies
1
. This enhancement simplifies and automates the migration process of legacy firewall solutions to distributed firewall, significantly reducing migration cost and speeding up security posture improvements3
.The capabilities are included in vDefend Security Services Platform 5.2, vDefend 9.1.1, Avi Load Balancer 32.1.4 and vACT 3.0, all compatible with VMware Cloud Foundation 9.1
1
. Watch for how these AI-era threats continue to evolve and whether enterprises adopt multi-layer cyber defense strategies at the pace required to counter AI-assisted attacks.Summarized by
Navi
[1]
[3]
26 Aug 2025•Technology

05 Nov 2024•Technology

18 Jun 2025•Technology

1
Technology

2
Science and Research

3
Technology
