VMware vDefend

 View Only

Agentic Zero Trust and Threat Defense: New VMware vDefend and Avi Load Balancer Innovations for Agentic AI

By Michelle Plato posted 13 days ago

  

Explore 2026 Product Announcement

By Umesh Mahajan

 

To address the new blind spots and security risks emerging from Agentic AI adoption, we are further enhancing our comprehensive multi-layer security stack in VMware vDefend (vDefend) and VMware Avi Load Balancer (Avi) to further secure these new workloads from Day 1. We are announcing plans to deliver Agentic Zero Trust and Agentic Threat Defense capabilities for vDefend and Avi, a comprehensive suite of security capabilities that enables enterprises to safely operationalize agentic AI with defense-in-depth for their private cloud. Read more about the announcement here.

VMware vDefend: Agentic Zero Trust

The following new vDefend enhancements will extend its Zero Trust lateral security to agentic AI workloads:

  • Discover Agentic AI Components: Gain comprehensive visibility by identifying all Agentic AI components, such as MCP servers, LLMs, tools, and datastores, across the environment, helping to ensure the security team has full visibility with no blind spots.
  • Shadow AI Monitoring: Maintain full control and compliance by identifying unauthorized AI usage and enforcing policies to mitigate shadow AI risk, enabling safer AI adoption. 

By continuously monitoring all traffic flows within VMware Cloud Foundation, vDefend can discover agentic AI endpoints, including authorized and unauthorized components. It also matches the performance and latency demands of AI workloads with a distributed, hypervisor-native architecture, delivering superior throughput with minimal impact on latency.

  • AI-Generated IDPS Signatures: Shield vulnerable workloads with AI-generated signatures produced at machine scale and speed, providing distributed virtual patching to help defend against the high volume and velocity of AI-discovered vulnerabilities.

Frontier AI now discovers and weaponizes vulnerabilities faster than human teams can manually author signatures, so we must use AI to fight AI. To keep pace, we are implementing an agentic AI pipeline that generates IDPS signatures at machine speed and scale. This pipeline takes input from vulnerability databases (incl. PSIRTs and CVEs) to generate signatures, while a parallel AI system rigorously tests and validates each one before it is integrated into our threat intelligence feed.

Avi Web Security: Agentic Threat Defense

Avi, with its zero-touch integration with Kubernetes including VMware vSphere Kubernetes Service (VKS), multi-terabit performance, elastic scale-out operation and latency analytics is ideally suited to deliver AI-aware load balancing, resilience and web application security and API protection (WAAP) to agentic AI workloads. The following new enhancements will broaden its protection of agentic AI workloads:  

  • Tool and Agent Misuse Prevention: Eliminate Malicious Exploits and safeguard your operations by restricting unauthorized agent access and blocking threats like remote code execution or file injection in real-time. 
  • Zero Day Attack Detection: Stay ahead of emerging attacks with automated behavioral baselines that flag and isolate anomalous activity, providing immediate defense against unknown threats.
  • Sensitive Data Protection: Help detect and stop the exfiltration of credentials, financial information, and personally identifiable information (PII) before they leave your network.

Together, these capabilities give agentic AI workloads content security, protection for tools and agents, early detection of unknown threats, and rich visibility, all within the load balancing layer.

Conclusion: Securing Agentic AI

As agentic AI solutions gain adoption, enterprises require a proactive strategy to securely deploy and manage these applications. By combining the Agentic Zero Trust capabilities of VMware vDefend with the Agentic Threat Defense of the VMware Avi Load Balancer, enterprises can confidently scale their agentic AI workloads. Together, these solutions provide the visibility needed to manage both authorized and shadow AI, the agility to mitigate zero-day threats with distributed virtual patching, and the control required to help prevent data exfiltration. With a foundation of Agentic Zero Trust and Agentic Threat Defense, organizations can unlock the full potential of Agentic AI innovation without compromising their enterprise security posture.

Resources

Note: The product direction information in this blog is for informational purposes only and may not be incorporated into any contract. There is no commitment or obligation to deliver any roadmap items presented herein.

Find the blog above here: https://www.broadcom.com/company/news/articles/cloud/agentic-zero-trust-threat-defense-vmware-vdefend-avi 

Read Umesh's blog about Multi-Layer Security Built for the AI Era if you haven't already.

0 comments
1 view

Permalink