VMware office in Bellevue, Washington - SDx crop
– JHVEPhoto/Getty Images

Broadcom has refreshed VMware’s security offerings with a raft of updates from VMware Explore 2025.

Offered as an add-on to the VMware Cloud Foundation (VCF) platform, the new VCF Advanced Cyber Compliance is touted as providing integrated compliance operations at scale.

The solution combines the automation capabilities of VCF SaltStack for remote execution and configuration management, with automated cyber and disaster recovery, and secure image support for Ubuntu containers.

Building on top of current configurations in VCF Automation, the update sees SaltStack integrations through the VCF Operations console. According to VMware, this allows large-scale automated monitoring and desired-state remediation, enabling continuous compliance across VCF environments while removing visibility silos.

The VCF Advanced Cyber Compliance is also designed to deliver fully automated cyber and disaster recovery within VCF’s data clean rooms, to enable secure collaboration through the sharing of protected and anonymized data.

The suite also includes built-in push-button VM network isolation. The inclusion enables prompt recovery from ransomware incidents and IT disruptions with end-to-end cyber recovery workflows and integrated validation tools covering both fileless and file-based malware. Automated operational cloning, backup, and restore capabilities are also included in the offering.

“Compliance management and infrastructure management … will be a key part of this advanced service queue,” said Umesh Mahajan, VP and GM of Broadcom's Application Networking and Security Division.

“We will also provide secure images for Ubuntu containers as well as key data services and databases with enterprise support. [This means] highly regulated industries will have secure images with a limited threat surface.”

The Ubuntu support comes with the mainline platform’s integration of VCF with Canonical’s Ubuntu Pro operating system, alongside integration of Ubuntu’s Kubernetes-based Chiseled containers.

VMware Avi and agentic AI

VMware is also bolstering security across VMware Avi Load Balancer (Avi), introducing a mutual transport layer security (mTLS) to allow both client and server to authenticate one another and bolster Kubernetes traffic.

Avi will also include a built-in Web Application Firewall (WAF) assessment tool that is promised to let teams both promptly evaluate their exposure to web-layer attacks and generate a security report.

The multi-cloud application delivery platform is also being updated in light of mooted threats to networking in the form of agentic workloads and the forthcoming Quantum Apocalypse.

Following in the footsteps of security providers such as Palo Alto Networks, Fortinet, and F5, the offering now includes National Institute of Standards and Technology (NIST)-approved post-quantum cryptography algorithms.

Additionally, Avi is introducing preview controls for the Model Context Protocol (MCP), an open standard introduced by AI firm Anthropic to standardize the way AI systems – in particular, large language models (LLMs) – integrate and communicate with external data sources, tools, and systems.

In the preview, traffic using MCP is protected by a web application firewall, while the system keeps sessions persistent and enforces authorization, narrowing the attack surface created by AI workloads.

According to Mahajan, the move is “very, very important [as] the whole world is moving to MCP”; recent months have seen both Oracle and Google Cloud introduce MCP-related updates in light of agentic AI workloads on the network.

That workload was reflected in another preview, available in VMware’s vDefend security suite, which adds Zero Trust lateral security specifically for agentic AI workloads running on VCF.

This comes alongside vDefend updates, including automation to accelerate Zero-Trust segmentation and clean up firewall rules, a data-centre-wide network detection and response sensor for broad threat visibility, and an antimalware scan interface-powered blocking of fileless in-memory malware.