<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VMware Security Blog</title>
	<atom:link href="https://blogs.vmware.com/security/feed" rel="self" type="application/rss+xml" />
	<link>https://blogs.vmware.com/security/</link>
	<description></description>
	<lastBuildDate>Thu, 06 Aug 2026 12:42:51 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.6</generator>
<site xmlns="com-wordpress:feed-additions:1">240671509</site>	<item>
		<title>VMware vDefend Advances Multi-Layer Lateral Security, Deployment Automation and Performance for the Frontier AI Era</title>
		<link>https://blogs.vmware.com/security/2026/08/vdefend-ssp-for-frontier-ai-era.html</link>
		
		<dc:creator><![CDATA[Prashant Gandhi]]></dc:creator>
		<pubDate>Thu, 06 Aug 2026 12:57:51 +0000</pubDate>
				<category><![CDATA[Advanced Threat Prevention]]></category>
		<category><![CDATA[Lateral Security]]></category>
		<category><![CDATA[Virtual Patching]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84974</guid>

					<description><![CDATA[<div><img width="300" height="187" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" fetchpriority="high" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg 1170w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=300,187 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=768,480 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=1024,640 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=600,375 600w" sizes="(max-width: 300px) 100vw, 300px" /></div>
<p>New enhancements include a prescriptive workflow to accelerate Advanced Threat Prevention (ATP) deployment, an on-premises Malware Prevention System, comprehensive air-gapped support, an AI Assistant for firewall operations, major performance gains for the Distributed Firewall and Intrusion Detection and Prevention Service (IDPS), and automated migration tooling. Earlier in May, VMware vDefend delivered Self-Service Lateral Security for &#8230; <a href="https://blogs.vmware.com/security/2026/08/vdefend-ssp-for-frontier-ai-era.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/08/vdefend-ssp-for-frontier-ai-era.html">VMware vDefend Advances Multi-Layer Lateral Security, Deployment Automation and Performance for the Frontier AI Era</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="187" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg 1170w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=300,187 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=768,480 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=1024,640 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Getty-2269281871.jpg?resize=600,375 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p style="text-align: center;"><i><span style="font-weight: 400;">New enhancements include a prescriptive workflow to accelerate Advanced Threat Prevention (ATP) deployment, an on-premises Malware Prevention System, comprehensive air-gapped support, an AI Assistant for firewall operations, major performance gains for the Distributed Firewall and Intrusion Detection and Prevention Service (IDPS), and automated migration tooling.</span></i></p>
<p><span style="font-weight: 400;">Earlier in May, VMware vDefend delivered </span><a href="https://blogs.vmware.com/security/2026/05/vdefend-vcf-9-1-zero-trust.html"><span style="font-weight: 400;">Self-Service Lateral Security for VMware Cloud Foundation (VCF) 9.1</span></a><span style="font-weight: 400;">, featuring support for unified lateral threat prevention for VMs and VKS workloads, high-performance threat prevention with IDPS Turbo Mode, and enhanced distributed firewall capabilities. </span></p>
<p><span style="font-weight: 400;">As Frontier AI continues to reshape the threat landscape, enterprises face new challenges in securing, operating, and scaling their private clouds. Attackers are using Frontier AI to exploit software vulnerabilities at machine speed, and the rapid adoption of agentic AI is drastically expanding the attack surface. At the same time, fragmented tools and manual processes are slowing down security teams, while rising hardware costs make it difficult for organizations to scale efficiently. </span></p>
<p><span style="font-weight: 400;">VMware vDefend addresses these challenges with new innovations focused on three pillars: enhanced security, simplified operations, and optimized performance and resources.</span></p>
<p><span style="font-weight: 400;">The detailed innovations under these three pillars are as follows: </span></p>
<h2><span style="font-weight: 400;">1. Enhanced Security</span></h2>
<ul>
<li><b>Accelerated Advanced Threat Prevention with vDefend 1-2-3:</b><span style="font-weight: 400;"> Introduces a streamlined, three-step deployment workflow that accelerates time-to-value for </span><a href="https://www.vmware.com/products/security/vdefend-advanced-threat-prevention"><span style="font-weight: 400;">ATP</span></a><span style="font-weight: 400;">, enabling overextended IT teams to rapidly deploy defenses in just a few weeks instead of many months. </span></li>
<li><b>On-Premises Malware Prevention System</b><span style="font-weight: 400;">: Brings malware sandboxing on-prem, analyzing static and dynamic artifacts entirely within the local network. All vDefend capabilities are now fully supported on-prem.</span></li>
<li><b>Comprehensive Air-Gapped Support</b><span style="font-weight: 400;">: All vDefend capabilities are now fully supported in air-gapped environments. This deployment model enables secure, offline threat intelligence updates, allowing highly sensitive environments to stay up to date on the latest threat signatures without connecting to the cloud. </span></li>
</ul>
<h2><span style="font-weight: 400;">2. </span><span style="font-weight: 400;">Simplified Operations</span></h2>
<ul>
<li><b>AI Assistant:</b><span style="font-weight: 400;"> vDefend now includes AI Assistant to streamline lateral security operations. It embeds AI-powered automation directly into the platform to simplify firewall operations and troubleshooting.</span></li>
<li><b>Automated Migration to vDefend Distributed Firewall:</b><span style="font-weight: 400;"> This vACT enhancement simplifies and automates the migration of legacy, agent-based firewall solutions to DFW, significantly reducing migration costs and accelerating security posture.</span></li>
</ul>
<h2><span style="font-weight: 400;">3. Optimized Performance and Resources</span></h2>
<ul>
<li><b>Distributed Firewall Performance Improvements</b><span style="font-weight: 400;">: To secure data-heavy AI workloads, vDefend significantly enhances Distributed Firewall (DFW) throughput to 22 Gbps on 25G NIC servers (a 129% increase) and 75 Gbps on 100G NIC servers (an additional 241% increase), achieving up to 75 Tbps scale-out performance per VCF instance.</span></li>
<li><b>Distributed Intrusion Detection and Prevention System Performance</b><span style="font-weight: 400;">: vDefend can now boost Intrusion Detection and Prevention System (IDPS) performance to 17Gbps per server (an 89% increase), delivering up to 17 Tbps of scale-out performance for distributed virtual patching per VCF instance.</span></li>
<li><b>Leaner Security Services Platform Deployment Model</b><span style="font-weight: 400;">: vDefend introduces a leaner Security Services Platform (SSP) deployment model that reduces the physical hardware required to run the platform, lowering infrastructure costs. </span></li>
</ul>
<p><span style="font-weight: 400;">The sections below describe each vDefend innovation in detail and highlight customer benefits. </span></p>
<h3>vDefend 1-2-3 for ATP: Deployment Automation Workflows</h3>
<p><span style="font-weight: 400;">Infiltration occurs when network traffic goes uninspected; therefore, implementing IDPS across all workloads, not just mission-critical ones, is essential. Additionally, robust network security requires zero-day threat detection and mitigation capabilities.  </span></p>
<p><span style="font-weight: 400;">vDefend 1-2-3 for ATP is a new guided workflow that accelerates the deployment of Advanced Threat Prevention across private cloud environments. Designed similarly to the </span><a href="https://blogs.vmware.com/security/2025/11/vdefend-dfw-1-2-3-4-vcf.html"><span style="font-weight: 400;">vDefend 1-2-3-4 for DFW</span></a><span style="font-weight: 400;"> workflow for lateral (macro and micro) segmentation, ATP workflow streamlines the implementation of IDPS, Network Traffic Analysis (NTA), and Network Detection and Response (NDR), reducing deployment times from months to weeks.</span></p>
<p><span style="font-weight: 400;">The workflow consists of three stages:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Stage 1:</b><span style="font-weight: 400;"> Conducts a threat posture assessment focused on IDPS, NTA, and NDR to evaluate current risks and provide recommendations.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Stage 2:</b><span style="font-weight: 400;"> Applies recommended IDPS policies to protect shared services infrastructure, such as Active Directory, DNS, and NTP.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Stage 3:</b><span style="font-weight: 400;"> Expands IDPS policies across zones (environments) such as DMZ, Dev, and Production.</span></li>
</ul>
<p><span style="font-weight: 400;">By using this guided workflow, IT teams can rapidly deploy Advanced Threat Prevention, including virtual patching and zero-day threat mitigation, to strengthen security posture and compliance.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png"><img decoding="async" class="wp-image-85014 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?w=1024" alt="" width="656" height="339" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png 4117w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?resize=300,155 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?resize=768,397 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?resize=1024,529 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?resize=1536,794 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?resize=2048,1059 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/vDefend_123_v2.png?resize=600,310 600w" sizes="(max-width: 656px) 100vw, 656px" /></a></p>
<h3>On-Premises Malware Prevention System</h3>
<p><span style="font-weight: 400;">Highly regulated industries face strict data sovereignty requirements and compliance standards such as HIPAA and GDPR, which make it essential to keep sensitive data and files inside local data centers. vDefend now offers an on-premises Malware Prevention System (MPS) that meets these requirements without compromising threat detection. This architecture brings malware sandboxing directly into the local data center, eliminating the need to upload files to an external public cloud. By keeping all sensitive data, files, and metadata strictly inside local boundaries, enterprises remove external attack surfaces while maintaining full control over their sensitive data.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png"><img decoding="async" class="wp-image-85002 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png?w=1024" alt="" width="520" height="349" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png 1160w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png?resize=300,201 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png?resize=768,515 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png?resize=1024,687 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/on-premises-MPS.png?resize=600,402 600w" sizes="(max-width: 520px) 100vw, 520px" /></a></p>
<h3>Comprehensive Air-Gapped Support</h3>
<p><span style="font-weight: 400;">For infrastructure requiring absolute operational isolation and strict data privacy, defending against modern threats without exposing internal systems to the internet is critical. </span></p>
<p><span style="font-weight: 400;">vDefend now offers a comprehensive, air-gapped deployment model to keep all network traffic, files, and data strictly inside the local data center. It eliminates external dependencies and public cloud connectivity. Security teams can safely download offline threat intelligence updates and manually upload them to vDefend. This maintains up-to-date signatures against new threats without connecting to external cloud services.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png"><img loading="lazy" decoding="async" class="wp-image-84981 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png?w=1024" alt="" width="543" height="366" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png 1160w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png?resize=300,202 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png?resize=768,518 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png?resize=1024,690 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image2.png?resize=600,404 600w" sizes="auto, (max-width: 543px) 100vw, 543px" /></a></p>
<h3>AI Assistant for vDefend</h3>
<p><span style="font-weight: 400;">Complex workflows and troubleshooting slow infrastructure and security teams down, consuming time, introducing risk, and holding back business agility. To reduce this complexity, VMware is introducing an AI Assistant for vDefend. By embedding intelligence directly into the platform, the tool accelerates troubleshooting, provides version-aware design guidance, and automates policy cleanup to eliminate duplicate and redundant rules. It also offers real-time visibility into live configurations, performance metrics, security events, and API assistance for automation. This operational intelligence allows security teams to streamline day-to-day operations and improve overall efficiency.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png"><img loading="lazy" decoding="async" class="wp-image-85003 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png?w=1024" alt="" width="540" height="349" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png 1172w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png?resize=300,194 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png?resize=768,497 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png?resize=1024,662 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/AI-Assistant.png?resize=600,388 600w" sizes="auto, (max-width: 540px) 100vw, 540px" /></a></p>
<h3>Leaner Security Services Platform (SSP) for Lower-Footprint Entry Point</h3>
<p><span style="font-weight: 400;">Enterprise IT teams need deep traffic visibility and security posture assessments to manage security risks effectively. The Security Services Platform (SSP) serves as a scale-out data lake that ingests network flow records and telemetry, providing granular flow visibility, security assessment scores, policy recommendations, and guided workflows. With rising server costs, vDefend now offers a leaner SSP deployment model with a lower-footprint entry point starting at 32 CPU cores. This new deployment model reduces physical server requirements by up to 33%, allowing organizations to lower infrastructure costs. The scale-out architecture of the SSP platform allows it to expand as needs grow.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png"><img loading="lazy" decoding="async" class="wp-image-84983 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png?w=1024" alt="" width="537" height="356" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png 1192w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png?resize=300,199 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png?resize=768,509 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png?resize=1024,679 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image5.png?resize=600,398 600w" sizes="auto, (max-width: 537px) 100vw, 537px" /></a></p>
<h3>Enhanced Distributed Firewall and IDPS Performance</h3>
<p><span style="font-weight: 400;">vDefend delivers major performance improvements across both the Distributed Firewall (DFW) and IDPS engines. </span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;"><b>Distributed Firewall: </b>DFW can now scale up to 22 Tbps (129% increase) and 75 Tbps (further 241% increase) per VCF instance using 25G and 100G NIC servers, respectively. With server costs on the rise, these enhancements allow enterprises to scale performance-intensive workloads using their existing server hardware via a software upgrade.</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;"><b>Distributed IDPS</b>: IDPS now delivers up to 17 Gbps per host, providing up to 17 Tbps (89% increase) scale-out capacity per VCF instance. These enhancements allow organizations to run hypervisor-native distributed virtual patching and secure performance-intensive AI traffic at scale, all delivered via a software upgrade.<br />
<a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png"><img loading="lazy" decoding="async" class="wp-image-85005 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?w=1024" alt="" width="588" height="278" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png 4399w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?resize=300,142 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?resize=768,363 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?resize=1024,484 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?resize=1536,727 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?resize=2048,969 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/08/SSP-Performance-v3.png?resize=600,284 600w" sizes="auto, (max-width: 588px) 100vw, 588px" /></a></span></li>
</ul>
<h3>Automated Migration to vDefend Distributed Firewall</h3>
<p><span style="font-weight: 400;">Migrating from legacy, agent-based firewall solutions is often slow and resource-intensive due to the manual effort required to translate complex rule sets. To eliminate this deployment friction, VMware offers the vDefend and Avi Conversion Tool (vACT) to automate security policy migrations. The tool automatically converts existing firewall rules and configurations directly into native vDefend policies. By accelerating transition and minimizing manual errors, vACT enables organizations to reduce overall migration costs and improve lateral security posture more quickly.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png"><img loading="lazy" decoding="async" class="wp-image-84985 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png?w=1024" alt="" width="556" height="376" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png 1156w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png?resize=300,203 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png?resize=768,520 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png?resize=1024,693 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/image4.png?resize=600,406 600w" sizes="auto, (max-width: 556px) 100vw, 556px" /></a></p>
<p><span style="font-weight: 400;">The new enhancements are delivered in vDefend Security Services Platform 5.2, vDefend 9.1.1, and vDefend and Avi Conversion Tool (vACT) 3.0 releases, all of which are compatible with the VCF private cloud 9.1 release.</span></p>
<h2>Lateral Defense for Agentic AI workloads</h2>
<p><span style="font-weight: 400;">As enterprises deploy agentic AI in their private cloud, Zero Trust lateral security will be necessary day one. Additionally, security technologies must recognize new agentic AI constructs, such as LLMs, agents, tools and AI protocols. One example is the Model Context Protocol (MCP), which enables agents to interact with various enterprise tools, data, and services. In addition to securing MCP traffic, it is important to harden the MCP itself in line with established enterprise-ready protocols like HTTP, SIP, SSH, and TLS. vDefend engineers took a leading role by championing a </span><a href="https://github.com/modelcontextprotocol/modelcontextprotocol/pull/3002#issuecomment-4987956893"><span style="font-weight: 400;">proposal</span></a><span style="font-weight: 400;"> to </span><span style="font-weight: 400;">harden stateless MCP interactions</span><span style="font-weight: 400;">, which is now reflected in Agentic AI Foundation’s </span><a href="https://modelcontextprotocol.io/docs/2026-07-28/"><span style="font-weight: 400;">updated MCP specification</span></a><span style="font-weight: 400;"> released in July 2026 (see coverage in the </span><a href="https://arstechnica.com/ai/2026/07/with-a-stateless-makeover-new-mcp-spec-targets-enterprise-scale/"><span style="font-weight: 400;">Ars Technica</span></a><span style="font-weight: 400;"> article). </span><span style="font-weight: 400;">Such collaborations are critical for achieving the visibility and policy enforcement required to secure agentic AI workloads</span><span style="font-weight: 400;">.</span></p>
<h2><span style="font-weight: 400;">Conclusion</span></h2>
<p><span style="font-weight: 400;">Modern enterprises require a multi-layer private cloud lateral defense that is distributed, automated, and high-performance to protect workloads against evolving, AI-driven threats. The latest vDefend enhancements further strengthen the solution through streamlined Advanced Threat Prevention workflows, flexible deployment models for highly sensitive environments, AI-assisted firewall operations, and significantly improved distributed firewall and IDPS performance. Together, these innovations enable security teams to stay ahead of threats and ensure the robust, multi-layer security required for modern private clouds.</span></p>
<p><span style="font-weight: 400;">To learn more about vDefend, see the links below.</span></p>
<h3><span style="font-weight: 400;">Resources</span></h3>
<ul>
<li><span style="font-weight: 400;">Dark Reading: </span><a href="https://www.darkreading.com/cloud-security/why-virtual-patching-and-multi-layer-defense-are-critical-in-the-age-of-frontier-ai"><span style="font-weight: 400;">Why Virtual Patching and Multi-Layer Defense are Critical in the Age of Frontier AI</span></a></li>
<li><a href="https://www.vmware.com/video/6399851996112"><span style="font-weight: 400;">Multi-layer Defense in the AI Era</span></a></li>
<li><a href="https://blogs.vmware.com/security/2026/05/vdefend-vcf-9-1-zero-trust.html"><span style="font-weight: 400;">VMware vDefend for VCF 9.1: Zero Trust Lateral Security for the AI Era</span></a></li>
<li><a href="https://blogs.vmware.com/security/2025/11/vdefend-dfw-1-2-3-4-vcf.html"><span style="font-weight: 400;">vDefend DFW 1-2-3-4: Deploy Zero Trust Microsegmentation</span></a></li>
<li><a href="https://blogs.vmware.com/security/2026/03/vdefend-kubernetes-workloads-vcf.html"><span style="font-weight: 400;">Zero Trust Lateral Security for Kubernetes Workloads on VCF</span></a></li>
<li><a href="https://blogs.vmware.com/security/2026/02/zero-trust-journey-vdefend.html"><span style="font-weight: 400;">Advancing Zero Trust Private Cloud with vDefend Lateral Security</span></a></li>
<li><a href="https://blogs.vmware.com/cloud-foundation/2026/04/29/avi-and-vdefend-for-vsphere-kubernetes-service/"><span style="font-weight: 400;">Enhance Lateral Security and Ingress Load Balancing for Kubernetes Workloads</span></a></li>
<li><a href="https://news.broadcom.com/explore/vmware-explore-2025-application-networking-and-security"><span style="font-weight: 400;">Broadcom Unveils AI-Ready Lateral Security and App Delivery Innovations</span></a></li>
<li><a href="https://go-vmware.broadcom.com/vDefend-Webinar-Series"><span style="font-weight: 400;">vDefend Webinar Series</span></a></li>
<li><span style="font-weight: 400;">Customer Case Studies:  </span><a href="https://www.vmware.com/resources/customers/st-johns-health-protects-private-cloud"><span style="font-weight: 400;">St. John’s Health</span></a><span style="font-weight: 400;"> | </span><a href="https://www.vmware.com/resources/customers/ussfcu-enhances-financial-wellness-with-a-vmware-private-cloud"><span style="font-weight: 400;">United States Senate Federal Credit Union</span></a><span style="font-weight: 400;"> | </span><a href="https://www.vmware.com/resources/customers/gci-closes-the-digital-divide-in-alaska-with-vmware"><span style="font-weight: 400;">GCI</span></a></li>
</ul>
<p>&nbsp;</p><p>The post <a href="https://blogs.vmware.com/security/2026/08/vdefend-ssp-for-frontier-ai-era.html">VMware vDefend Advances Multi-Layer Lateral Security, Deployment Automation and Performance for the Frontier AI Era</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84974</post-id>	</item>
		<item>
		<title>VMware vDefend Sessions at VMware Explore 2026</title>
		<link>https://blogs.vmware.com/security/2026/07/vmware-vdefend-sessions-at-vmware-explore-2026.html</link>
		
		<dc:creator><![CDATA[Soumen Chatterjee]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 08:55:26 +0000</pubDate>
				<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Lateral Security]]></category>
		<category><![CDATA[VCF Security]]></category>
		<category><![CDATA[VMware Explore]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84919</guid>

					<description><![CDATA[<div><img width="300" height="169" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png 1921w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=300,169 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=768,432 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=1024,576 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=1536,864 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=600,338 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>Ready to learn how to secure your private cloud workloads against a new wave of AI-driven threats while accelerating your Private Cloud and App modernization journey? VMware Explore returns to the Venetian Convention and Expo Center in Las Vegas from August 31 – Sep. 03, 2026. Step into the next generation of enterprise infrastructure and &#8230; <a href="https://blogs.vmware.com/security/2026/07/vmware-vdefend-sessions-at-vmware-explore-2026.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/07/vmware-vdefend-sessions-at-vmware-explore-2026.html">VMware vDefend Sessions at VMware Explore 2026</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="169" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png 1921w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=300,169 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=768,432 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=1024,576 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=1536,864 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/vmx26-general-tagline_1920X1080_v2.png?resize=600,338 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><span style="font-weight: 400;">Ready to learn how to secure your private cloud workloads against a new wave of AI-driven threats while accelerating your Private Cloud and App modernization journey? VMware Explore returns to the Venetian Convention and Expo Center in Las Vegas from August 31 – Sep. 03, 2026. Step into the next generation of enterprise infrastructure and see firsthand how VMware vDefend delivers comprehensive lateral security for VMware Cloud Foundation workloads in the Agentic AI era.</span></p>
<p><span style="font-weight: 400;">Gain expertise and a competitive edge by learning what vDefend offers in today’s rapidly changing threat landscape. Catch the sessions below at VMware Explore 2026 to chart your organization’s future and protect your private cloud. </span></p>
<p><span style="font-family: Metropolis-Medium, Helvetica, sans-serif; font-size: 1.125rem;">Executive Highlight Session</span></p>
<p style="text-align: center;"><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg"><img loading="lazy" decoding="async" class="wp-image-84952 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?w=1024" alt="" width="611" height="407" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg 3000w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?resize=300,200 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?resize=768,512 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?resize=1024,683 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?resize=1536,1024 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?resize=2048,1365 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/9P6A1229NSLB1756LV.jpg?resize=600,400 600w" sizes="auto, (max-width: 611px) 100vw, 611px" /></a><em>Umesh Mahajan at VMware Explore 2025</em></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*115879s*_ga*NTM3MTkxMzU5LjE3MTUxMDYxNTc.*_ga_8VJHMNGE3E*czE3ODMzNjgzNTEkbzU0OSRnMCR0MTc4MzM2ODM1MSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=Umesh#_gl=1*bfahxf*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2" target="_blank" rel="noopener"><span style="font-weight: 400;">Operationalizing Cyber Defense and App Resilience for the Agentic AI Era [SECB1789LV]</span></a><span style="font-weight: 400;"><br />
Tuesday, Sep 1  2:00 PM &#8211; 2:45 PM PDT</span></h3>
<p><span style="font-weight: 400;">Digital IT is adopting agentic AI to help businesses further differentiate and boost productivity. AI is also the cause of attack surface explosion, as bad actors armed with the same AI models autonomously infiltrate enterprises. Infrastructure operators need new innovations that accelerate their AI journey, while ensuring app resilience and complete cyber lockdown of large language models (LLMs), agents, data stores, and MCP services. Join Umesh Mahajan, GM of Application Networking and Security (ANS), Broadcom, to learn how IT is consuming lateral security and app delivery for AI and non-AI workloads. The session will cover operational best practices to implement Zero Trust and app resilience Day 1 for VMware Cloud Foundation® (VCF) 9.1 and private AI, leveraging new innovations in VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> and VMware® Avi<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Load Balancer. The deployment journey will focus on rapid rollout to buy-down risk while ensuring app availability, investment protection, and consistent operations of VMs, VMware vSphere® Kubernetes Service, and agentic AI workloads.</span></p>
<p>Umesh Mahajan<span style="font-weight: 400;">, VP &amp; GM, Application Networking and Security, Broadcom<br />
Prashant Gandhi, Head of Products, Application Networking and Security, Broadcom<br />
</span></p>
<h2><span style="font-weight: 400;">People&#8217;s Choice Award Winner &#8211; Breakout Session</span></h2>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*14pm08s*_ga*NTM3MTkxMzU5LjE3MTUxMDYxNTc.*_ga_8VJHMNGE3E*czE3ODQ1Nzk2NzgkbzU3MCRnMCR0MTc4NDU3OTY3OCRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1079#_gl=1*1f2u65c*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2LjI4OTI5Nzk0My4xNzg0NTYzMDU2LjE3ODQ1NjMwNjMuMTU0MDY5MzE1OC4xNzg0NTYzMDU2LjE3ODQ1NjMwNjM." target="_blank" rel="noopener"><span style="font-weight: 400;">Enforcing Zero Trust for Apps Across Multi-Cluster VMware vSphere Kubernetes Service [SECB1079LV]</span></a><span style="font-weight: 400;"><br />
Tuesday, Sep 1  10:15 AM &#8211; 11:00 AM PDT<br />
</span></h3>
<p><span style="font-weight: 400;">As VMware vSphere® Kubernetes Service (VMware VKS) becomes the go-to runtime for running modern applications and especially AI applications on VMware Cloud Foundation® (VCF), how do you enforce strict Zero Trust for workloads across multiple Kubernetes clusters and VMs? In this session, we will show how SecOps can define a central &#8220;security taxonomy&#8221; via labels, and how developers deploy apps that automatically consume those policies. We will look at how VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> and Antrea CNI work together to enforce microsegmentation across VKS clusters from a single control plane. We will cover: • Building a label-based taxonomy for Kubernetes apps • Enforcing Zero Trust with vDefend and Antrea across L4 • Protecting L7 with end-to-end mTLS and WAF using Istio and VMware® Avi<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> • Ensuring bad actors cannot bypass global security • Automating policy rollouts via Terraform. Finally, we will wrap up with a demo showing this entire automated workflow in action.</span></p>
<p>Chris McCain, <span style="font-weight: 400;">Field CTO, Broadcom<br />
</span> Niran Evenchen,<b> <span style="font-weight: 400;">Principal Solution Architect, Broadcom</span></b></p>
<h2><span style="font-weight: 400;">Breakout Sessions</span></h2>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*42ofcr*_ga*NTM3MTkxMzU5LjE3MTUxMDYxNTc.*_ga_8VJHMNGE3E*czE3ODQwNTk0MzYkbzU2MSRnMSR0MTc4NDA1OTY1OCRqMzIkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1247#_gl=1*11ucvpl*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2LjExNjUzMTAwNzUuMTc4NDA1OTQ0MC4xNzg0MDU5NDcz" target="_blank" rel="noopener"><span style="font-weight: 400;">Lateral Security Simplified: The VMware vDefend Distributed Firewall 1-2-3-4 Security Journey [SECB1247LV]</span></a><br />
<span style="font-weight: 400;">Monday, Aug 31  9:00 AM &#8211; 9:45 AM PDT</span></h3>
<p><span style="font-weight: 400;">Stopping lateral movement within the data center is critical, yet many organizations struggle with the complexity of mapping and securing east-west traffic. The VMware vDefend Security Journey provides a prescriptive, data-driven workflow designed to simplify lateral security for VMware Cloud Foundation®. In this session, we break down the &#8220;1-2-3-4&#8221; deployment framework to help you move from zero visibility to a fully hardened environment. We will walk through the four essential stages: protecting critical shared services, segmenting broad environments, securing specific application tiers, and achieving final lockdown. Whether you are starting from scratch or refining your firewall, you will leave with a practical roadmap to eliminate lateral threats.</span></p>
<p>Catherine Fan<span style="font-weight: 400;">, Technology Product Manager, Broadcom<br />
Andrew Hrycaj, Technical Product Manager, Broadcom<br />
</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*4rmyu8*_ga*NTMzMTUyOTQ5LjE3NjU1NzgzMzQ.*_ga_8VJHMNGE3E*czE3ODMzNzcwMDEkbzE3OCRnMCR0MTc4MzM3NzAwMSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1358#_gl=1*i0b8n1*_gcl_au*NTYyMTU1NTkyLjE3ODMzNzcwMDE." target="_blank" rel="noopener"><span style="font-weight: 400;">Demystifying vDefend Distributed Security within VMware Cloud Foundation [SECB1358LV]</span></a><br />
<span style="font-weight: 400;">Monday, Aug 31  10:15 AM &#8211; 11:00 AM PDT</span></h3>
<p><span style="font-weight: 400;">VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Distributed Firewall and VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Distributed Intrusion Detection and Prevention System (IDS/IPS) provide security services in the kernel through processing of rules and signatures intrinsically within the virtual networking infrastructure. We will show the inner workings of the distributed services from an architectural standpoint and, more importantly, the best implementation techniques, as well as troubleshooting tools for examining the effectiveness of the strategy deployed. We will show the use of AI to simplify the configuration of the centrally managed protection mechanisms and greatly reduce the time and effort needed to put a tight security policy in place.</span></p>
<p>Chris McCain<span style="font-weight: 400;">, Field CTO, Broadcom<br />
</span>Tim (vGandalf) Burkard<span style="font-weight: 400;">, Principal Technical Learning Engineer, Broadcom</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*4rmyu8*_ga*NTMzMTUyOTQ5LjE3NjU1NzgzMzQ.*_ga_8VJHMNGE3E*czE3ODMzNzcwMDEkbzE3OCRnMCR0MTc4MzM3NzAwMSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1119#_gl=1*i0b8n1*_gcl_au*NTYyMTU1NTkyLjE3ODMzNzcwMDE." target="_blank" rel="noopener"><span style="font-weight: 400;">Self-Service Security for VMware Cloud Foundation Automation with VMware vDefend Distributed Firewall [SECB1119LV]</span></a><br />
<span style="font-weight: 400;">Tuesday, Sep 1  9:00 AM &#8211; 9:45 AM PDT</span></h3>
<p><span style="font-weight: 400;">The core of delivering a VMware Cloud Foundation (VCF) private cloud experience to enterprise customers and cloud service providers is empowering their project and tenant admins with delegated, self-service security controls. This session will explore how VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Distributed Firewall delivers these self-service capabilities directly to customers consuming the VCF private cloud via VCF Automation. We will specifically discuss delegating vDefend Distributed Firewall controls and how enterprise admins, providers, and tenant admins can leverage it to ensure the highest levels of security.</span></p>
<p>Geoff Wilmington<span style="font-weight: 400;">, Technology Product Management, Broadcom</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?search=SECB1466LV&amp;tab.sessioncatalogtabs=1747347809815001igUo#_gl=1*bfahxf*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2" target="_blank" rel="noopener"><span style="font-weight: 400;">Prescriptive Ransomware Defense for VMware Cloud Foundation Workloads with VMware vDefend Advanced Threat Prevention [SECB1466LV]</span></a><br />
<span style="font-weight: 400;">Tuesday, Sep 1   3:15 PM &#8211; 4:00 PM PDT</span></h3>
<p><span style="font-weight: 400;">Ransomware is pervasive; your defense must be proactive. For VMware Cloud Foundation® (VCF) users, the optional phase of security is over. Join us to discover how to leverage VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Advanced Threat Prevention, including IDS/IPS, NTA, and NDR to stay ahead of threat actors. Whether you are just getting started or looking to optimize your existing stack, you will learn about a new prescriptive, built-in guided workflow with assessments and tailored security policies that will significantly improve your security posture.</span></p>
<p>Bopaiah Puliyanda<span style="font-weight: 400;">, Senior Manager, Product Management, Broadcom</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*4rmyu8*_ga*NTMzMTUyOTQ5LjE3NjU1NzgzMzQ.*_ga_8VJHMNGE3E*czE3ODMzNzcwMDEkbzE3OCRnMCR0MTc4MzM3NzAwMSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1630#_gl=1*i0b8n1*_gcl_au*NTYyMTU1NTkyLjE3ODMzNzcwMDE." target="_blank" rel="noopener"><span style="font-weight: 400;">Security Reference Design for VMware Cloud Foundation [SECB1630LV]</span></a><br />
<span style="font-weight: 400;">Wednesday, Sep 2  11:30 AM &#8211; 12:15 PM PDT</span></h3>
<p><span style="font-weight: 400;">In the era of decentralized data and AI-driven threats, security can no longer be a bolt-on feature—it must be the foundation. As organizations consolidate on VMware Cloud Foundation® (VCF), the challenge shifts from managing disparate security tools to implementing a unified, Zero Trust architecture that protects workloads from the silicon up to the cloud. Join us as we break down the blueprint for a hardened VCF and learn how to design security for VCF management and workload domains. We will move beyond basic configuration to explore a holistic architectural approach that integrates VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> lateral security solutions. We will walk through the framework for building a resilient VCF private cloud: infrastructure protection, application ring fencing and microsegmentation, threat visibility, and ransomware prevention.</span></p>
<p>Pooja Patel<span style="font-weight: 400;">, Director, Broadcom</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?search=SECB1462LV&amp;tab.sessioncatalogtabs=1747347809815001igUo#_gl=1*bfahxf*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2" target="_blank" rel="noopener"><span style="font-weight: 400;">Secure the Front Door: Hardened VMware vSphere Kubernetes Service with VMware Avi<br />
and VMware vDefend [SECB1462LV]</span></a><br />
<span style="font-weight: 400;">Wednesday, Sep 2  12:45 PM &#8211; 1:30 PM PDT</span></h3>
<p><span style="font-weight: 400;">Kubernetes (K8s) introduces a dramatically more agile model for modern applications. VMware® Avi<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> and VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> deliver critical security and load balancing for K8s workloads. VMware Avi and Avi Kubernetes Operator (AKO) redefine Kubernetes ingress by eliminating manual networking &#8220;plumbing.&#8221; Within VMware vSphere® Kubernetes Service (VMware VKS), installation is plug-and-play: AKO automatically provisions enterprise load balancing the moment your cluster is live. We are future-proofing this stack via the K8s Gateway API—the industry standard for modern AI Gateways. This role-oriented model simplifies life for developers and admins, providing the &#8220;front door&#8221; required for next-gen apps. Security remains a core pillar through Istio integration, where VMware Avi delivers high-performance mTLS, WAF, and deep observability. The session also highlights a top U.S. financial institution’s design and architecture for AKO. This unified approach ensures your VMware VKS environment is secure, modern, and simple to operate at scale.</span></p>
<p>Chris Grice<span style="font-weight: 400;">, Technical Product Manager, Broadcom<br />
Madhu Krishnarao, Sr. Product Manager, Broadcom</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?search=SECB1279LV&amp;tab.sessioncatalogtabs=1747347809815002itcH#_gl=1*bfahxf*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2" target="_blank" rel="noopener"><span style="font-weight: 400;">The Patching Dilemma: Do You Need Help with the Deluge of Vulnerabilities? [SECB1279LV]</span></a><br />
<span style="font-weight: 400;">Wednesday, Sep 2  2:00 PM &#8211; 2:45 PM PDT</span></h3>
<p><span style="font-weight: 400;">The gap between vulnerability discovery and exploitation is shrinking at an unprecedented rate. As AI-driven tools automate the identification of zero-day flaws, traditional patch-all strategies have become mathematically impossible for modern enterprises. How do we keep up when the deluge never ends? This session explores a shift from reactive patching to risk-based orchestration. We will dive into the critical role of compensating controls, specifically focusing on how Virtual Patching via IDPS (Intrusion Detection and Prevention Systems) and Avi Web Application Firewall (WAF) provides the breathing room teams desperately need. Attendees will learn how to buy back time for testing and deployment without leaving their environment exposed to the next major exploit.</span></p>
<p>Geoff Shukin<span style="font-weight: 400;">, Senior Product Manager, Broadcom<br />
Stijn Vanveerdeghem, Senior Manager, Technology Product Management, Broadcom<br />
</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*42ofcr*_ga*NTM3MTkxMzU5LjE3MTUxMDYxNTc.*_ga_8VJHMNGE3E*czE3ODQwNTk0MzYkbzU2MSRnMSR0MTc4NDA1OTY1OCRqMzIkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1311#_gl=1*11ucvpl*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2LjExNjUzMTAwNzUuMTc4NDA1OTQ0MC4xNzg0MDU5NDcz" target="_blank" rel="noopener"><span style="font-weight: 400;">Secure by Design: Eliminating Ransomware Blind Spots with VMware vDefend [SECB1311LV]</span></a><br />
<span style="font-weight: 400;">Wednesday, Sep 2  3:15 PM &#8211; 4:00 PM PDT</span></h3>
<p><span style="font-weight: 400;">In a landscape where lateral movement defines modern attacks, infrastructure can no longer be a passive bystander. This session explores a security-first approach that embeds defense directly into the hypervisor to neutralize threats at the source. We provide a deep dive into the unique architectural advantage of VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> and VMware Cloud Foundation® (VCF), demonstrating a methodology to &#8220;buy down&#8221; risk across your entire environment. Through technical insights and an end-to-end demo, you will discover how to achieve immediate &#8220;quick wins&#8221; such as virtual patching and distributed threat prevention to stop attackers before they gain a foothold.</span></p>
<p>Stijn Vanveerdeghem<span style="font-weight: 400;">, Senior Manager, Technology Product Management, Broadcom</span></p>
<h2><span style="font-weight: 400;">Innovation Track</span></h2>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*4rmyu8*_ga*NTMzMTUyOTQ5LjE3NjU1NzgzMzQ.*_ga_8VJHMNGE3E*czE3ODMzNzcwMDEkbzE3OCRnMCR0MTc4MzM3NzAwMSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1744#_gl=1*i0b8n1*_gcl_au*NTYyMTU1NTkyLjE3ODMzNzcwMDE." target="_blank" rel="noopener"><span style="font-weight: 400;">Governance of Micro-Segmentation Policies [INVB1744LV]</span></a><br />
<span style="font-weight: 400;">Wednesday, Sep 2  3:15 PM &#8211; 4:00 PM PDT</span></h3>
<p><span style="font-weight: 400;">This session explores the critical pillars of microsegmentation governance, moving beyond the initial visibility phase into sustainable, long-term policy management. We will dissect the lifecycle of a policy—from discovery and authoring to automated enforcement and continuous auditing.</span></p>
<p>Kausum Kumar<span style="font-weight: 400;">, Senior Manager, Technical Product Management, Broadcom</span></p>
<p>&nbsp;</p>
<p style="text-align: center;"><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg"><img loading="lazy" decoding="async" class="wp-image-84931 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?w=1024" alt="" width="736" height="552" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg 4600w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?resize=300,225 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?resize=768,576 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?resize=1024,768 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?resize=1536,1152 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?resize=2048,1536 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/Explore-2025-theater_cropped-1.jpeg?resize=600,450 600w" sizes="auto, (max-width: 736px) 100vw, 736px" /></a><em>Theater presentation at VMware Explore 2025</em></p>
<div class="rf-attribute speakers-component" data-test="speakers-component">
<div class="session-details speaker-details" data-test="session-participants-area">
<p data-test="participant-info-1714623760731001QKEN_1769448explore2026lv"><span style="font-family: Metropolis-Medium, Helvetica, sans-serif; font-size: 1.125rem;">Tutorials</span></p>
</div>
</div>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*4rmyu8*_ga*NTMzMTUyOTQ5LjE3NjU1NzgzMzQ.*_ga_8VJHMNGE3E*czE3ODMzNzcwMDEkbzE3OCRnMCR0MTc4MzM3NzAwMSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1642#_gl=1*i0b8n1*_gcl_au*NTYyMTU1NTkyLjE3ODMzNzcwMDE." target="_blank" rel="noopener"><span style="font-weight: 400;">A Step-by-Step Tutorial for Stopping Brickstorm-Like Attacks Using VMware vDefend [SECT1642LV]</span></a><br />
<span style="font-weight: 400;">Monday, Aug 31  11:30 AM &#8211; 1:00 PM PDT</span></h3>
<p><span style="font-weight: 400;">This session provides step-by-step guidance about how VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> provides a robust architectural shield against such catastrophic events. We will dive into the deployment mechanics of VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Distributed Firewall and Distributed Intrusion Detection/Prevention (IDS/IPS) to demonstrate how micro-segmentation can effectively stop attacks in their infancy.</span></p>
<p>Andrew Hrycaj<span style="font-weight: 400;">, Technical Product Manager, Broadcom<br />
Geoff Shukin, Senior Product Manager, Broadcom</span></p>
<h2>Quick Talk</h2>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?search=1710&amp;_gl=1*115879s*_ga*NTM3MTkxMzU5LjE3MTUxMDYxNTc.*_ga_8VJHMNGE3E*czE3ODMzNjgzNTEkbzU0OSRnMCR0MTc4MzM2ODM1MSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo#_gl=1*bfahxf*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2" target="_blank" rel="noopener"><span style="font-weight: 400;">The Top 10 Agentic AI Security Risks and Threats Every IT Admin Should Know [CMTYQT1710LV]</span></a><br />
Monday Aug 31 11:00 AM &#8211; 11:20 AM PDT</h3>
<h3 class="title-text"><span style="font-family: Metropolis-Light, Helvetica, sans-serif; font-size: 1rem;">Learn about the top 10 security risks and vulnerabilities facing agentic AI applications, large language (LLMs), and MCP servers. In this session, we will provide an introductory overview of agentic AI components, real-world examples of AI security threats, and how you can prepare to mitigate those risks with VMware software solutions.</span></h3>
<div class="rf-attribute speakers-component" data-test="speakers-component">
<div class="session-details speaker-details" data-test="session-participants-area">
<p data-test="participant-info-1723472378957001ZYK5_1769448explore2026lv">Catherine Fan, Technology Product Manager, Broadcom<br />
Aziz Mohammed, Technical Product Manager, Broadcom</p>
</div>
</div>
<h2><span style="font-weight: 400;">Meet the Expert Roundtables</span></h2>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1748" target="_blank" rel="noopener"><span style="font-weight: 400;">Best Practices for Tagging and Groups for VMware vDefend Distributed Firewall [SECM1748LV]</span></a><br />
Monday, Aug 31 2:00 PM &#8211; 2:30 PM PDT</h3>
<div class="catalog-result-title session-title rf-simple-flex-frame">
<div class="catalog-result-title-text">
<h3 class="title-text"><span style="font-family: Metropolis-Light, Helvetica, sans-serif; font-size: 1rem;">In this session, we will explore how VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> leverages metadata—rather than network topography—to define security boundaries that are both elastic and resilient. This session includes details on implementing a robust tagging schema (e.g., environment, tier, data sensitivity) to provide the granular context required for Zero Trust. We will discuss developing a handful of readable, intent-based policies that apply across the entire private cloud.</span></h3>
</div>
<div>Kausum Kumar, Senior Manager, Technical Product Management, Broadcom</p>
</div>
</div>
<div></div>
<div>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?search=1710&amp;_gl=1*115879s*_ga*NTM3MTkxMzU5LjE3MTUxMDYxNTc.*_ga_8VJHMNGE3E*czE3ODMzNjgzNTEkbzU0OSRnMCR0MTc4MzM2ODM1MSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo#_gl=1*bfahxf*_gcl_au*MTM5MTI4MzYxNC4xNzgwNTEwNzU2" target="_blank" rel="noopener"><span style="font-weight: 400;">Blocking and Tackling Ransomware with VMware vDefend: Practical Tips and Insights [SECM1756LV]</span></a><br />
Tuesday, Sep 1  10:00 AM &#8211; 10:30 AM PDT</h3>
</div>
<p><span style="font-weight: 400;">In this interactive whiteboard session, we move past the high-level marketing slides to focus on the technical &#8220;blocking and tackling&#8221; required to secure your private cloud using VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" />. Among other topics, participants will gain technical insights into virtual patching, using Distributed IDS/IPS to shield vulnerable workloads from known exploits without the immediate need for disruptive guest-level patching, leveraging network detection and response (NDR) and sandboxing to identify behavioral signals of ransomware actors, and a lot more. Bring your questions and leave with a practical blueprint for making your infrastructure immune from ransomware.</span></p>
<p>Bopaiah Puliyanda<span style="font-weight: 400;">, Senior Manager, Product Management, Broadcom</span></p>
<h3><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog?_gl=1*4rmyu8*_ga*NTMzMTUyOTQ5LjE3NjU1NzgzMzQ.*_ga_8VJHMNGE3E*czE3ODMzNzcwMDEkbzE3OCRnMCR0MTc4MzM3NzAwMSRqNjAkbDAkaDA.&amp;tab.sessioncatalogtabs=1747347809815001igUo&amp;search=1509#_gl=1*i0b8n1*_gcl_au*NTYyMTU1NTkyLjE3ODMzNzcwMDE." target="_blank" rel="noopener"><span style="font-weight: 400;">Code-Driven Security: Automating VMware vDefend Policy with Infrastructure as Code [SECM1509LV]</span></a><br />
<span style="font-weight: 400;">Tuesday, Sep 1  2:00 PM &#8211; 2:30 PM PDT</span></h3>
<p><span style="font-weight: 400;">Stop managing security policies manually. This session moves beyond basic configuration to focus on operationalizing automation within your private cloud defense using infrastructure as code (IaC). We will demonstrate how to leverage code to automatically generate, deploy, and manage your VMware® vDefend<img src="https://s.w.org/images/core/emoji/16.0.1/72x72/2122.png" alt="™" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Policy, making security policy a function of code that protects your environment from the ground up. We will dive deep into practical methods for codifying network segmentation using vDefend with virtual private clouds (VPCs), defining granular role-based access, and standardizing critical defenses like Layer 4/7 Firewall and Gateway Firewall configurations. By operationalizing this IaC approach, you will ensure consistent, scalable, and secure resource provisioning across all your projects, leading to streamlined and reliable deployment strategies.</span></p>
<p>Andrew Hrycaj<span style="font-weight: 400;">, Technical Product Manager, Broadcom</span></p>
<p>&nbsp;</p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg"><img loading="lazy" decoding="async" class="wp-image-84949 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?w=1024" alt="" width="722" height="481" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg 3000w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?resize=300,200 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?resize=768,512 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?resize=1024,683 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?resize=1536,1024 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?resize=2048,1365 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/07/AU4A0662.jpg?resize=600,400 600w" sizes="auto, (max-width: 722px) 100vw, 722px" /></a></p>
<p>&nbsp;</p>
<p><span style="font-weight: 400;">Registration is now open! Check out the </span><a href="https://event.vmware.com/flow/vmware/explore2026lv/content/page/catalog" target="_blank" rel="noopener"><b>content catalog</b></a><span style="font-weight: 400;"> and scheduling tool, using the </span><strong><a href="https://event.vmware.com/my/widget/vmware/explore2026lv/1784562141363001rmMo" target="_blank" rel="noopener">vDefend</a></strong><span style="font-weight: 400;">,  </span><strong><a href="https://event.vmware.com/my/widget/vmware/explore2026lv/1784059569487001tEF6" target="_blank" rel="noopener">Avi</a></strong><span style="font-weight: 400;">, and overall </span><strong><a href="https://event.vmware.com/my/widget/vmware/explore2026lv/1784059552872001NZuO" target="_blank" rel="noopener">ANS</a></strong> Targeted Agendas<span style="font-weight: 400;"> to build your personalized VMware Explore schedule. Looking forward to seeing you in Las Vegas!</span></p><p>The post <a href="https://blogs.vmware.com/security/2026/07/vmware-vdefend-sessions-at-vmware-explore-2026.html">VMware vDefend Sessions at VMware Explore 2026</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84919</post-id>	</item>
		<item>
		<title>Validated Compliance: VMware vDefend Conforms with NIST CSF, HIPAA and PCI DSS</title>
		<link>https://blogs.vmware.com/security/2026/06/validated-compliance-vmware-vdefend-conforms-with-nist-csf-hipaa-and-pci-dss.html</link>
		
		<dc:creator><![CDATA[Soumen Chatterjee and Suman Sharma]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 21:14:28 +0000</pubDate>
				<category><![CDATA[Advanced Threat Prevention]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Lateral Security]]></category>
		<category><![CDATA[Workload Security]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84881</guid>

					<description><![CDATA[<div><img width="300" height="177" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1248867543.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1248867543.png 600w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1248867543.png?resize=300,177 300w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>VMware vDefend directly conforms to NIST CSF, HIPAA, and PCI DSS requirements, providing organizations with the critical controls needed to satisfy regulatory mandates and mitigate modern threats. Regulatory compliance has become a strategic imperative across all industry sectors due to a growing global focus on data privacy, supply chain transparency, and operational resilience. This urgency &#8230; <a href="https://blogs.vmware.com/security/2026/06/validated-compliance-vmware-vdefend-conforms-with-nist-csf-hipaa-and-pci-dss.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/06/validated-compliance-vmware-vdefend-conforms-with-nist-csf-hipaa-and-pci-dss.html">Validated Compliance: VMware vDefend Conforms with NIST CSF, HIPAA and PCI DSS</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="177" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1248867543.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1248867543.png 600w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1248867543.png?resize=300,177 300w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><i><span style="font-weight: 400;">VMware vDefend directly conforms to NIST CSF, HIPAA, and PCI DSS requirements, providing organizations with the critical controls needed to satisfy regulatory mandates and mitigate modern threats.</span></i></p>
<p><span style="font-weight: 400;">Regulatory compliance has become a strategic imperative across all industry sectors due to a growing global focus on data privacy, supply chain transparency, and operational resilience. This urgency is further amplified by the rapid adoption of AI and the rise of AI-accelerated cyberattacks. These advanced threats often target software vulnerabilities and spread laterally through east-west traffic to access high-value targets such as electronic protected health information (ePHI) or Cardholder Data Environment (CDE). As a result, security and compliance teams must deploy comprehensive controls to provide visibility and enforcement, restrict lateral movement, detect threats, and enable mitigation before damage can occur.</span></p>
<p><span style="font-weight: 400;">To effectively address these challenges and ensure compliance, organizations must align their security architecture with the necessary control points. This alignment is typically achieved through a layered approach, using regulatory frameworks tailored to their industry, data type, and security maturity:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>The Strategic Baseline (NIST CSF 2.0):</b><span style="font-weight: 400;"> A highly flexible, risk-based set of guidelines (Identify, Protect, Detect, Respond, Recover). It is often used as a baseline for overall cybersecurity maturity or mapped to fulfill other requirements.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>The Prescriptive Mandates (PCI DSS 4.0.1 &amp; HIPAA):</b><span style="font-weight: 400;"> These granular, rules-driven standards are designed to safeguard specialized assets such as cardholder data and ePHI, requiring robust technical boundaries, workload isolation, and deep traffic surveillance.</span></li>
</ul>
<p><span style="font-weight: 400;">To provide an objective, professional evaluation of vDefend&#8217;s alignment with these mandates, VMware partnered with </span>Coalfire<span style="font-weight: 400;">, a leading independent cybersecurity advisory firm. This partnership resulted in the publication of authoritative </span><b>Product Applicability Guides (PAGs)</b><span style="font-weight: 400;">, which provide a detailed assessment of VMware vDefend&#8217;s capabilities against established regulatory requirements.</span></p>
<p><span style="font-weight: 400;">VMware vDefend is a comprehensive Zero Trust lateral security solution designed to protect against cyber threats. This hypervisor-native, software-defined solution provides deep visibility into both network and application activities, effectively eliminating security blind spots. It enforces a multi-layered defense and mitigation strategy against ransomware and advanced persistent threats. </span></p>
<p><span style="font-weight: 400;">VMware vDefend is a comprehensive lateral security solution that includes multiple capabilities: distributed and gateway firewalls (DFW, GFW), distributed Intrusion Detection and Prevention Service (IDS/IPS), Malware Prevention Service (MPS), Network Detection and Response (NDR) with an NDR Sensor, and Network Traffic Analysis (NTA). This solution offers deep traffic visibility and creates a closed-loop security system for VCF private cloud, ensuring visibility, prevention, detection, and mitigation of cyber threats.</span></p>
<p><span style="font-weight: 400;">The following sections explore how VMware vDefend aligns with the essential lifecycle mandates of these critical compliance frameworks.</span></p>
<h2>The Strategic Baseline: NIST CSF 2.0</h2>
<p><span style="font-weight: 400;">The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0 serves as a foundation for modern security design. Rather than offering a simple checklist, it presents a systematic approach organized around five key technical functions: Identify, Protect, Detect, Respond, and Recover.</span></p>
<p><span style="font-weight: 400;">The following sections detail how vDefend&#8217;s comprehensive security capabilities align with the objectives of each NIST framework function.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png"><img loading="lazy" decoding="async" class="wp-image-84888 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png?w=1024" alt="" width="739" height="365" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png 1390w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png?resize=300,148 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png?resize=768,379 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png?resize=1024,505 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image4.png?resize=600,296 600w" sizes="auto, (max-width: 739px) 100vw, 739px" /></a></p>
<h3>Identify</h3>
<p><span style="font-weight: 400;">Proper identification and mapping of various critical IT assets form the foundation of a comprehensive defense strategy. With vDefend, enterprises can organize workloads statically or dynamically using a </span><b><i>tag-based</i></b><span style="font-weight: 400;"> labeling system to trigger specific security policies. Static policies apply to a fixed set of tagged workloads, while dynamic policies automatically adjust and apply based on ‌specific tags. This dynamic enforcement ensures that the corresponding level of compliance, be it regulatory (e.g., HIPAA, PCI DSS) or internal security posture requirements, is met instantly and consistently as new workloads are spun up or existing ones change.</span></p>
<p><span style="font-weight: 400;">VMware vDefend’s </span><b><i>Security Intelligence</i></b><span style="font-weight: 400;"> provides real-time, distributed visibility across the entire data center and cloud infrastructure by continuously monitoring and analyzing all identified traffic flows between workloads. By observing these communication patterns, the Security Intelligence platform can automatically detect and map the &#8220;desired&#8221; or &#8220;baseline&#8221; behavior of applications. Based on this traffic flow analysis, the platform provides highly calibrated, actionable policy recommendations that can significantly reduce the attack surface and enhance the overall security posture.</span></p>
<p><span style="font-weight: 400;">With a clearly identified asset inventory and defined policy baselines, the focus then shifts to proactive enforcement.</span></p>
<h3>Protect</h3>
<p><span style="font-weight: 400;">Protecting enterprise workloads from known and previously unseen (zero-day) threats is a core capability of the vDefend solution.</span></p>
<p><span style="font-weight: 400;">While vDefend Gateway Firewall (GFW) provides conventional NGFW edge controls, albeit with a modern software-defined architecture, the vDefend Distributed Firewall (DFW) employs a distributed (and scale-out) &#8216;security-per-workload&#8217; model, ‌securing each workload at the virtual NIC layer. Lateral movement, the technique in which attackers pivot from a compromised system to high-value targets, is the primary mechanism by which modern threats, such as sophisticated ransomware and advanced persistent threats, spread internally. By enforcing security policies for every workload, vDefend DFW effectively stops unauthorized lateral movement and restricts breaches from spreading. This critical defense-in-depth mechanism dramatically shrinks the attack surface to an individual workload.</span></p>
<p><span style="font-weight: 400;">While the Distributed Firewall restricts spread, continuous detection is required to flag anomalies and sophisticated threats that bypass conventional defenses.</span></p>
<h3>Detect</h3>
<p><span style="font-weight: 400;">The Detect function focuses on identifying a cybersecurity event in real time, not just after the fact, enabling rapid response and containment. In today&#8217;s dynamic threat landscape, this function has undergone a significant transformation. vDefend Advanced Threat Prevention (ATP) has evolved the detection capability by leveraging a multi-layered approach to threat detection, ensuring that security gaps are minimized and evasive threats are captured:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Distributed Intrusion Detection/Prevention System (IDS/IPS):</b><span style="font-weight: 400;"> The vDefend distributed IDS/IPS inspects network traffic and actively matches traffic patterns against an extensive, continuously updated library of over 10,000 known threat and vulnerability signatures. This distributed deep inspection – applied on a per-workload basis – is crucial for detecting both external attacks and east-west traffic anomalies, and for identifying potential vulnerabilities before they can be exploited.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Network Traffic Analysis (NTA):</b><span style="font-weight: 400;"> NTA detects highly sophisticated attacks that bypass perimeter defenses by using behavioral analytics and machine learning on network metadata and flow information. NTA excels at immediately flagging subtle signs of an ongoing internal breach, particularly lateral movement, a key indicator of a successful intrusion.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Sandboxing for Malware Analysis:</b><span style="font-weight: 400;"> vDefend provides an advanced sandboxing feature to neutralize the threat of zero-day exploits and polymorphic malware. This technology isolates suspicious files and URLs in a secure, virtualized environment (the &#8220;sandbox&#8221;), where the file is &#8220;detonated&#8221; or executed within a limited blast radius to observe the true behavior. If the file exhibits malicious characteristics, it is blocked, and the signature information is updated to prevent future occurrences.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Network Detection and Response (NDR)</b><span style="font-weight: 400;">: vDefend NDR correlates multiple disparate data points from various sources into visually intuitive attack maps. These detailed, chronological, and graphical representations of an attack campaign result in highly relevant, actionable security intelligence for security teams. </span></li>
</ul>
<p><span style="font-weight: 400;">Taken together, these capabilities give organizations a holistic, real-time picture of threats across their environment. The comprehensive, correlated data and visual attack maps also serve as verifiable evidence of due diligence during audits.</span></p>
<h3>Respond</h3>
<p><span style="font-weight: 400;">The response involves a rapid, coordinated incident management effort to contain threats and minimize damage. </span></p>
<p><span style="font-weight: 400;">When a threat is detected, vDefend can automatically trigger a Quarantine Policy, moving the infected VM into an isolated &#8220;Security Group&#8221; with access limited to forensics tools. When coupled with correlated intrusion campaign data from NDR, the incident management team can visualize the entire attack chain on a map. Furthermore, vDefend’s advanced troubleshooting tools—such as traceflow, packet capture, and detailed firewall logs—provide the forensic data needed to demonstrate compliance during an audit.</span></p>
<p><span style="font-weight: 400;">Once the immediate threat is contained and the attack chain is documented, the final step is ensuring full operational recovery.</span></p>
<h3>Recover</h3>
<p><span style="font-weight: 400;">The Recover function focuses on the rapid and complete restoration of services to the pre-incident operational state, ensuring the integrity of all reinstated data. VMware vDefend offers robust capabilities for incremental and full configuration backups. Furthermore, integrating VMware Live Recovery with vDefend significantly enhances the overall resilience strategy, covering both incident response and subsequent recovery.</span></p>
<p><span style="font-weight: 400;">In summary, the VMware vDefend solution enables foundational security controls that not only provide enterprise-grade protection but also streamlines the complex process of achieving and maintaining continuous compliance across diverse regulatory landscapes. Coalfire&#8217;s evaluation recognizes vDefend for its excellent structural coverage throughout the entire NIST lifecycle.</span></p>
<p><span style="font-weight: 400;">Coalfire assessed vDefend against all 106 subcategories in NIST CSF 2.0, and the results demonstrate the breadth and depth of vDefend&#8217;s compliance coverage. vDefend achieves full or strong coverage across the vast majority of applicable subcategories. The ability to monitor, inspect, and enforce policy on east-west traffic within a VCF environment is the architectural advantage that drives this coverage, translating directly into measurable, assessor-validated outcomes across Identify, Protect, Detect, and Respond.</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1_83f827.png"><img loading="lazy" decoding="async" class="wp-image-84886 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1_83f827.png?w=758" alt="" width="438" height="200" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1_83f827.png 758w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1_83f827.png?resize=300,137 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1_83f827.png?resize=600,274 600w" sizes="auto, (max-width: 438px) 100vw, 438px" /></a></p>
<p><span style="font-weight: 400;">It is worth noting that NIST CSF 2.0 is intentionally broad — many of its subcategories address organizational and business processes that extend beyond any single technology platform. vDefend delivers deep, validated coverage of the technical control layer, and when combined with the organizational security program built around it, organizations are strongly positioned to demonstrate comprehensive CSF 2.0 alignment.<br />
</span><span style="font-weight: 400;"><br />
</span><span style="font-weight: 400;">The detailed NIST CSF 2.0 Product Applicability Guide is available </span><a href="https://www.vmware.com/docs/WP_vDefend_CSF_2026"><span style="font-weight: 400;">here</span></a><span style="font-weight: 400;">. </span></p>
<h2>The Prescriptive Mandates: PCI DSS 4.0.1 &amp; HIPAA</h2>
<p><span style="font-weight: 400;">In contrast to the broad NIST framework, data-specific regulations such as PCI DSS and HIPAA involve highly prescriptive technical requirements. Whether securing credit card data or electronic health records, vDefend serves as an essential, independently validated technical control point for both standards. The sections below explain these in detail.</span></p>
<h3>PCI DSS 4.0.1 Alignment</h3>
<p><span style="font-weight: 400;">The Payment Card Industry Data Security Standard places a strong emphasis on isolating the Cardholder Data Environment (CDE) and restricting access to it. In a virtualized environment, this means enforcing precise east-west traffic controls—the core architecture vDefend is built around. Coalfire&#8217;s Product Applicability Guide highlights vDefend&#8217;s coverage across all 12 major PCI DSS requirements:</span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png"><img loading="lazy" decoding="async" class="wp-image-84885 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png?w=1024" alt="" width="800" height="449" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png 1999w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png?resize=300,168 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png?resize=768,431 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png?resize=1024,575 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png?resize=1536,862 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image2.png?resize=600,337 600w" sizes="auto, (max-width: 800px) 100vw, 800px" /></a></p>
<p><span style="font-weight: 400;">Note: Requirements 3 and 9 are marked N/A as they address stored account data and physical access controls, respectively — areas outside the scope of a network security platform.</span></p>
<p><span style="font-weight: 400;">The detailed PCI DSS 4.0.1 Applicability Guide is available </span><a href="https://www.vmware.com/docs/broadcom-vmware-vdefend-product-applicability-guide-for-pci-dss"><span style="font-weight: 400;">here</span></a><span style="font-weight: 400;">. </span></p>
<h3>HIPAA Technical Safeguards Mapping</h3>
<p><span style="font-weight: 400;">In healthcare environments, the stakes of inadequate security controls are particularly high. East-west traffic between clinical applications, databases, and administrative systems creates a wide attack surface for ePHI exposure. vDefend directly addresses this risk through its distributed enforcement model.</span></p>
<p><span style="font-weight: 400;">Under the HIPAA Security Rule, healthcare covered entities must deploy specific technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Coalfire’s validation confirms that vDefend aligns directly with these rigorous provisions: </span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png"><img loading="lazy" decoding="async" class="wp-image-84884 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png?w=1024" alt="" width="772" height="424" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png 1999w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png?resize=300,165 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png?resize=768,422 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png?resize=1024,563 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png?resize=1536,844 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image3.png?resize=600,330 600w" sizes="auto, (max-width: 772px) 100vw, 772px" /></a></p>
<p><span style="font-weight: 400;">The Administrative Safeguards (requirements 1–5) address process and access governance; the Technical Safeguards (requirements 6–9) enforce those controls at the system level. vDefend is independently validated across all nine, providing covered entities with a strong, documentable compliance foundation.</span></p>
<p><span style="font-weight: 400;">The detailed HIPAA Applicability Guide can be found </span><a href="https://www.vmware.com/docs/broadcom-vmware-vdefend-product-applicability-guide-for-hipaa"><span style="font-weight: 400;">here</span></a><span style="font-weight: 400;">. </span></p>
<p><span style="font-weight: 400;">VMware vDefend provides essential technical control points for data-specific regulations. Coalfire&#8217;s validation confirms its direct alignment with both the PCI DSS 4.0.1 requirements for isolating the Cardholder Data Environment (CDE) and the HIPAA Security Rule&#8217;s rigorous provisions for safeguarding the confidentiality, integrity, and availability of ePHI.</span></p>
<h2>Conclusion</h2>
<p><span style="font-weight: 400;">VMware vDefend delivers a comprehensive set of control points for both broad frameworks, such as NIST CSF, and data-specific compliance mandates, such as PCI DSS and HIPAA. Adopting VMware vDefend allows organizations to implement a robust security strategy while gaining the necessary control points for compliance. By integrating visibility, prevention, detection, and mitigation directly into a closed-loop security system, vDefend significantly accelerates an organization&#8217;s journey toward a Zero Trust posture and continuous compliance. </span></p>
<p><span style="font-weight: 400;">To learn more about the benefits of vDefend, see the links below.</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><a href="https://www.vmware.com/docs/broadcom-vmware-vdefend-product-applicability-guide-for-pci-dss"><span style="font-weight: 400;">vDefend Product Applicability Guide for PCI-DSS</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://www.vmware.com/docs/broadcom-vmware-vdefend-product-applicability-guide-for-hipaa"><span style="font-weight: 400;">vDefend Product Applicability Guide for HIPAA</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://www.vmware.com/docs/WP_vDefend_CSF_2026"><span style="font-weight: 400;">vDefend Product Applicability Guide for NIST CSF 2.0</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://www.vmware.com/products/security/vdefend-distributed-firewall"><span style="font-weight: 400;">VMware vDefend Distributed Firewall</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://www.vmware.com/products/security/vdefend-advanced-threat-prevention"><span style="font-weight: 400;">VMware vDefend Advanced Threat Prevention</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://www.vmware.com/docs/vmw-vdefend-ds"><span style="font-weight: 400;">VMware vDefend Datasheet</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://blogs.vmware.com/security/2025/11/vdefend-dfw-1-2-3-4-vcf.html"><span style="font-weight: 400;">vDefend DFW 1-2-3-4: A Prescriptive Path to Zero Trust Microsegmentation</span></a></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://youtube.com/playlist?list=PLdYldEmmLm2mhuuzkcQx20B07Y_r67NeK&amp;si=uETHEvFxe_Mns4ha"><span style="font-weight: 400;">VMware vDefend How to Videos on YouTube</span></a></li>
</ul>
<p>&nbsp;</p><p>The post <a href="https://blogs.vmware.com/security/2026/06/validated-compliance-vmware-vdefend-conforms-with-nist-csf-hipaa-and-pci-dss.html">Validated Compliance: VMware vDefend Conforms with NIST CSF, HIPAA and PCI DSS</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84881</post-id>	</item>
		<item>
		<title>Introducing VMware vDefend Lateral Security Design Blueprints for  VCF 9.1</title>
		<link>https://blogs.vmware.com/security/2026/06/vdefend-design-blueprints-vcf-9-1.html</link>
		
		<dc:creator><![CDATA[Nikodim Nikodimov]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 21:18:35 +0000</pubDate>
				<category><![CDATA[Misc]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84866</guid>

					<description><![CDATA[<div><img width="300" height="171" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg 1170w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=300,171 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=768,438 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=1024,585 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=600,343 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>In the past, data center security mostly relied on perimeter protection—&#8221;building walls&#8221; to keep bad actors out. Today, safeguarding the data center&#8217;s &#8220;east-west&#8221; or lateral traffic traversing within applications and data is just as critical. Threat actors are leveraging &#8220;Frontier AI&#8221; security models to automate and accelerate attacks against private cloud workloads.  To help enterprises &#8230; <a href="https://blogs.vmware.com/security/2026/06/vdefend-design-blueprints-vcf-9-1.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/06/vdefend-design-blueprints-vcf-9-1.html">Introducing VMware vDefend Lateral Security Design Blueprints for  VCF 9.1</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="171" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg 1170w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=300,171 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=768,438 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=1024,585 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/GettyImages-1493136853.jpg?resize=600,343 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><span style="font-weight: 400;">In the past, data center security mostly relied on perimeter protection—&#8221;building walls&#8221; to keep bad actors out. Today, safeguarding the data center&#8217;s &#8220;east-west&#8221; or lateral traffic traversing within applications and data is just as critical. Threat actors are leveraging &#8220;Frontier AI&#8221; security models to automate and accelerate attacks against private cloud workloads. </span></p>
<p><span style="font-weight: 400;">To help enterprises achieve best-of-breed protection with significantly reduced complexity, we are excited to announce new VMware vDefend blueprints to speed up lateral security roll-out across VCF private cloud workloads and help organizations quickly buy down risk. The &#8220;Lateral Security for VMware Cloud Foundation with VMware vDefend&#8221; VVS is now integrated into core VCF 9.1 design documentation as &#8220;Lateral Security with vDefend&#8221; Blueprints. The blueprints for Securing the Management and Workload domains are now included with the core VCF 9.1 design documentation.</span></p>
<p><span style="font-weight: 400;">Here is a closer look at what this change means, what these blueprints cover, and how you can start using them to modernize your private cloud security and protect against both conventional and AI attacks.</span></p>
<h2>What are the Design Blueprints for VMware Cloud Foundation?</h2>
<p><span style="font-weight: 400;">A blueprint is a prescriptive, end-to-end architecture designed to accelerate your time-to-value when building and operating a VMware Cloud Foundation (VCF) private cloud platform. It provides predefined deployment models that conform to specific profiles. A blueprint also includes a set of planning, implementation, and design elements (requirements and recommendations) tailored to the selected deployment model. You can streamline your VCF private cloud provisioning by using them as a template, swapping out models to match your unique infrastructure layout.</span></p>
<h2>What does Lateral Security with vDefend Blueprints cover?</h2>
<p><span style="font-weight: 400;">The Lateral Security with vDefend Blueprints describes the architectural components and design selections required to provide unified, enterprise-grade security services for a VMware Cloud Foundation platform using VMware vDefend security solutions.</span></p>
<p><span style="font-weight: 400;">The design consists of three individual blueprints that cover pre-defined models to address network and application security corners of your platform:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/design/design-blueprints-for/security-modernization/vdefend-lateral-security/security-services-platform-for-vmware-cloud-foundation.html"><b>Security Services Platform for VCF</b></a><span style="font-weight: 400;">: Outlines the design details, planning and preparation, and implementation steps for deploying the </span><a href="https://blogs.vmware.com/security/2025/03/vdefend-microsegmentation.html"><span style="font-weight: 400;">vDefend Security Services Platform</span></a><span style="font-weight: 400;"> on VCF.</span></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/design/design-blueprints-for/security-modernization/vdefend-lateral-security/vcf-management-domain-security.html"><b>Management Domain Security</b></a><span style="font-weight: 400;">: Tailored guidelines to protect the critical management components powering the VCF and establish a foundational, security-robust private cloud environment.</span></li>
<li style="font-weight: 400;" aria-level="1"><a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/design/design-blueprints-for/security-modernization/vdefend-lateral-security/vcf-workload-domain-security.html"><b>Workload Domain Security</b></a><span style="font-weight: 400;">: Dedicated blueprint aimed at utilizing the </span><a href="https://blogs.vmware.com/security/2025/11/vdefend-dfw-1-2-3-4-vcf.html"><span style="font-weight: 400;">vDefend DFW-1-2-3-4</span></a><span style="font-weight: 400;"> staged prescriptive workflow to meet the Zero Trust lateral security model for applications within a VCF workload domain.</span></li>
</ul>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png"><img loading="lazy" decoding="async" class="wp-image-84867 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?w=1024" alt="" width="799" height="432" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png 1999w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?resize=300,162 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?resize=768,416 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?resize=1024,554 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?resize=1536,831 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?resize=410,222 410w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png?resize=600,325 600w" sizes="auto, (max-width: 799px) 100vw, 799px" /></a></p>
<h2>Getting Started</h2>
<p><span style="font-weight: 400;">Ready to eliminate blind spots and lock down your east-west traffic? Check out the new </span><a href="https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/design/design-blueprints-for/security-modernization/vdefend-lateral-security.html"><span style="font-weight: 400;">Lateral Security with vDefend design blueprints</span></a><span style="font-weight: 400;"> today and take your private cloud security to the next level</span><span style="font-weight: 400;">.</span></p>
<h2>Summary</h2>
<p><span style="font-weight: 400;">By integrating VMware Validated Solutions into the core VCF 9.1 design documents, Broadcom aims to streamline documentation and provide straightforward guidance for building a robust, secure private cloud.</span></p>
<p><span style="font-weight: 400;">The Lateral Security with vDefend Blueprints equips you with verified configurations and guidelines to streamline setup, reduce guesswork, and accelerate the path to a cyber-resilient private cloud. Whether you&#8217;re new to security or an experienced professional, these blueprints make it easier than ever to transform your security plans into a practical security strategy.</span></p>
<p>Deployment and Design Resources:</p>
<p><a href="https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/design-library-for-vdefend/index.html">Design Library for vDefend</a></p>
<p><a style="background-color: #ffffff; font-size: 1rem;" href="https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/design-library-for-vdefend/index/securing-vks.html">Securing vSphere Supervisor and VKS</a></p>
<p><a style="background-color: #ffffff; font-size: 1rem;" href="https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/design-library-for-vdefend/index/vdefend-1-2-3-4--security-journey-deployment-guide.html">DFW 1-2-3-4: Security Journey Self-Deployment Guide</a></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/06/image1.png"> </a></p><p>The post <a href="https://blogs.vmware.com/security/2026/06/vdefend-design-blueprints-vcf-9-1.html">Introducing VMware vDefend Lateral Security Design Blueprints for  VCF 9.1</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84866</post-id>	</item>
		<item>
		<title>AMD Ionic Driver Vulnerabilities Affecting VMware ESX</title>
		<link>https://blogs.vmware.com/security/2026/05/amd-ionic-driver-vulnerabilities-affecting-vmware-esx.html</link>
		
		<dc:creator><![CDATA[Praveen Singh]]></dc:creator>
		<pubDate>Tue, 12 May 2026 22:03:53 +0000</pubDate>
				<category><![CDATA[VMware Security Response Center]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84855</guid>

					<description><![CDATA[<div><img width="300" height="169" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg 640w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg?resize=300,169 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg?resize=600,338 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>We would like to bring your attention to a security bulletin from AMD: AMD-SN-2001: Ionic Driver Vulnerabilities. The bulletin details three vulnerabilities — CVE-2025-62623, CVE-2025-62624, and CVE-2025-62627 — present in the AMD ionic cloud driver for VMware ESX. These issues affect ESX hosts using AMD-Pensando DPU (Data Processing Unit) products. We strongly encourage you to &#8230; <a href="https://blogs.vmware.com/security/2026/05/amd-ionic-driver-vulnerabilities-affecting-vmware-esx.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/05/amd-ionic-driver-vulnerabilities-affecting-vmware-esx.html">AMD Ionic Driver Vulnerabilities Affecting VMware ESX</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="169" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg 640w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg?resize=300,169 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/95965143_xl.jpg?resize=600,338 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p class="p1"><span class="s1">We would like to bring your attention to a security bulletin from AMD: <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-2001.html">AMD-SN-2001: Ionic Driver Vulnerabilities</a>.</span></p>
<p class="p4"><span class="s1">The bulletin details three vulnerabilities — CVE-2025-62623, CVE-2025-62624, and CVE-2025-62627 — present in the AMD ionic cloud driver for VMware ESX. These issues affect ESX hosts using AMD-Pensando DPU (Data Processing Unit) products.</span></p>
<p class="p1"><span class="s1">We strongly encourage you to review the bulletin if you are using AMD-Pensando DPU products.<b></b></span></p>
<p class="p1"><span class="s1">For technical inquiries, please contact VMware Support for assistance.</span></p><p>The post <a href="https://blogs.vmware.com/security/2026/05/amd-ionic-driver-vulnerabilities-affecting-vmware-esx.html">AMD Ionic Driver Vulnerabilities Affecting VMware ESX</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84855</post-id>	</item>
		<item>
		<title>VMware at Pwn2Own Berlin 2026</title>
		<link>https://blogs.vmware.com/security/2026/05/vmware-at-pwn2own-berlin-2026.html</link>
		
		<dc:creator><![CDATA[Praveen Singh and Monty Ijzerman]]></dc:creator>
		<pubDate>Mon, 11 May 2026 21:51:25 +0000</pubDate>
				<category><![CDATA[VMware Security Response Center]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84851</guid>

					<description><![CDATA[<div><img width="300" height="170" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/pwn2ownberlin.jpeg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/pwn2ownberlin.jpeg 600w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/pwn2ownberlin.jpeg?resize=300,170 300w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>Update, July 29, 2026 Today, Broadcom has released the following new VMware security advisory: VMSA-2026-0006 &#8211; VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) The advisory documents the remediation of the Critical severity vulnerability (VMXNET3 out-of-bounds write vulnerability- CVE-2026-47876) demonstrated at the Pwn2Own 2026 hacking contest. Customers should review &#8230; <a href="https://blogs.vmware.com/security/2026/05/vmware-at-pwn2own-berlin-2026.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/05/vmware-at-pwn2own-berlin-2026.html">VMware at Pwn2Own Berlin 2026</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="170" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/pwn2ownberlin.jpeg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/pwn2ownberlin.jpeg 600w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/pwn2ownberlin.jpeg?resize=300,170 300w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><strong>Update, July 29, 2026</strong></p>
<p>Today, Broadcom has released the following new VMware security advisory:</p>
<p><strong><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017">VMSA-2026-0006</a> &#8211; VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709)</strong></p>
<p>The advisory documents the remediation of the Critical severity vulnerability (VMXNET3 out-of-bounds write vulnerability- CVE-2026-47876) demonstrated at the <a href="https://www.zerodayinitiative.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026">Pwn2Own 2026</a> hacking contest. Customers should review the security advisory and direct any questions to <a href="https://support.broadcom.com/web/ecx/software-contact-support" name="&amp;lpos=apps_scodevmw : 45">VMware Support</a>.</p>
<p class="p1"><strong><span class="s1">Update, May 16, 2026</span></strong></p>
<p class="p2"><span class="s2">Pwn2Own 2026 has finished and we have witnessed one successful attempt on our products. On May 16, 2026, Nguyen Hoang Thach of STARLabs SG successfully demonstrated an exploit targeting VMware ESX. </span></p>
<p class="p1"><span class="s1">We are actively working on the remediation and we plan to publish a VMware Security Advisory to provide information on updates for the affected products.</span></p>
<p class="p1"><span class="s1">We would like to thank the Zero Day Initiative (ZDI) for allowing us to participate and the team from STARLabs SG for working with us to address the reported issue.</span></p>
<p class="p1"><strong><span class="s1">Initial post</span></strong></p>
<p>The Broadcom PSIRT Team (VCF Division) is pleased to announce VMware&#8217;s participation in <a href="https://www.zerodayinitiative.com/blog/2026/3/11/announcing-pwn2own-berlin-for-2026">Pwn2Own Berlin 2026</a>, organized by the Zero Day Initiative (ZDI). The competition will run from May 14–16, alongside <a href="https://www.offensivecon.org/">OffensiveCon</a> in Berlin, Germany.</p>
<p>Members of our team will be on-site to validate any VMescape demonstrations on ESX. If you are attending and have any questions for us, we would be happy to connect with you in-person.</p>
<p>VMware ESX continues to be a primary target in the virtualization category. A successful VMescape demonstration carries prize money of $150,000, with an additional $50,000 bonus available. This year, the contest is limited to ESX as VMware Workstation has been removed from the competition&#8217;s target list.</p>
<p>We would like to thank the Zero Day Initiative (ZDI) for the opportunity to participate. We will update this post as additional details become available. To stay informed on the latest VMware Security Advisories (VMSAs), please <a href="https://go-vmware.broadcom.com/vmsa_email_alert">sign up here</a>.</p>
<p>&nbsp;</p><p>The post <a href="https://blogs.vmware.com/security/2026/05/vmware-at-pwn2own-berlin-2026.html">VMware at Pwn2Own Berlin 2026</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84851</post-id>	</item>
		<item>
		<title>VMware vDefend for VCF 9.1: Zero Trust Lateral Security for the AI Era</title>
		<link>https://blogs.vmware.com/security/2026/05/vdefend-vcf-9-1-zero-trust.html</link>
		
		<dc:creator><![CDATA[Prashant Gandhi]]></dc:creator>
		<pubDate>Tue, 05 May 2026 13:00:48 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Lateral Security]]></category>
		<category><![CDATA[advanced threat detection]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[Kubernetes Security]]></category>
		<category><![CDATA[VCF]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84825</guid>

					<description><![CDATA[<div><img width="300" height="162" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png 4500w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=300,162 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=768,414 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=1024,552 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=1536,827 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=2048,1103 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=410,222 410w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=600,323 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>New enhancements include Self-Service Lateral Security with VCF Automation, Unified Lateral Threat Prevention for VMs and VKS Workloads, High-Performance Threat Prevention with IDPS Turbo Mode, and Enhanced Distributed Firewall capabilities. The rapid adoption of production AI workloads is reshaping the enterprise technology landscape, driving the growth of Kubernetes environments alongside existing VM-based infrastructure. As organizations &#8230; <a href="https://blogs.vmware.com/security/2026/05/vdefend-vcf-9-1-zero-trust.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/05/vdefend-vcf-9-1-zero-trust.html">VMware vDefend for VCF 9.1: Zero Trust Lateral Security for the AI Era</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="162" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png 4500w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=300,162 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=768,414 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=1024,552 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=1536,827 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=2048,1103 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=410,222 410w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Getty-1420039900.png?resize=600,323 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p style="text-align: center;"><i><span style="font-weight: 400;">New enhancements include Self-Service Lateral Security with VCF Automation, Unified Lateral Threat Prevention for VMs and VKS Workloads, High-Performance Threat Prevention with IDPS Turbo Mode, and Enhanced Distributed Firewall capabilities.</span></i></p>
<p><span style="font-weight: 400;">The rapid adoption of production AI workloads is reshaping the enterprise technology landscape, driving the growth of Kubernetes environments alongside existing VM-based infrastructure. As organizations deploy AI agents and AI workloads across private cloud environments spanning VMs and Kubernetes, the attack surface becomes larger and more dynamic. The result is a rapidly evolving threat landscape, driving the need to secure both VM- and Kubernetes-based environments efficiently and consistently.</span></p>
<p><span style="font-weight: 400;">Recent incidents, including the CISA-reported BRICKSTORM malware activity and the rise of AI-assisted semi-autonomous cyberattacks, underscore that adversaries are now operating at machine speed. At the same time, enterprises face several practical challenges: reducing the attack surface to prevent lateral propagation of threats, securing workloads at the speed of application deployments, enforcing consistent security across VMs and Kubernetes environments, delivering the performance required for AI and high-capacity workloads, and consolidating security within the core platform rather than relying on fragmented point solutions.</span></p>
<p><span style="font-weight: 400;">VMware vDefend is integrated with the VMware Cloud Foundation (VCF) platform, providing plug-and-play zero-trust lateral security that protects modern distributed workloads, including AI and high-performance computing, without compromising the performance and agility they demand.</span></p>
<p><span style="font-weight: 400;">vDefend&#8217;s hypervisor-native, distributed, software-defined model provides a closed-loop security architecture </span><span style="font-weight: 400;">that uniquely enables visibility, prevention,</span> <span style="font-weight: 400;">detection,</span> <span style="font-weight: 400;">and mitigation for comprehensive multi-layer defense. </span><span style="font-weight: 400;">Additionally, vDefend’s distributed policy orchestration allows policies to be created once and automatically enforced as workloads are created or moved.</span></p>
<h3><b>New vDefend innovations for VCF 9.1</b></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Self-Service Lateral Security with VCF Automation:</b> <span style="font-weight: 400;">VCF Automation&#8217;s Self-Service Lateral Security enables infrastructure and security teams to establish guardrails, such as predefined VPC security profiles and delegated distributed firewall (DFW) settings, allowing tenant admins to access security features on demand. This facilitates quicker application onboarding and ensures a uniform security baseline across all tenants.<br />
</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Unified Lateral Threat Prevention for VMs and VKS Workloads:</b> <span style="font-weight: 400;">As agentic AI and cloud-native applications drive Kubernetes adoption, VMware vSphere Kubernetes Service (VKS) clusters can now be inspected and protected by the same high-performance distributed IDS/IPS that currently secures VMs. Security teams get one console, one policy model, and consistent lateral threat prevention across VMs, containers, and bare-metal workloads, eliminating the blind spots attackers exploit. Customers deploy IDS/IPS (1) to meet compliance requirements (PCI-DSS and HIPAA) and (2) to enable virtual patching that quickly protects against software vulnerabilities while patches are rolled out enterprise-wide.<br />
</span></li>
<li style="font-weight: 400;" aria-level="1"><b>High-Performance Lateral Threat Prevention: </b><span style="font-weight: 400;"><span style="font-weight: 400;">The new IDPS Turbo Mode delivers 3x throughput, increasing from 3 Gbps to 9 Gbps per host and up to 9 Tbps per VCF domain, enabling security teams to protect against software vulnerabilities (virtual patching) and behavioral threat detection for modern AI and high-capacity workloads.</span></span></li>
<li style="font-weight: 400;" aria-level="1"><b>Enhanced Distributed Firewall Capabilities</b><span style="font-weight: 400;">:</span> <span style="font-weight: 400;">A 5x increase in Application Identification support for greater L7 visibility and simpler, granular security enforcement. Additionally, identity-based firewalling now supports a federated (multi-site) environment for consistent, simplified policy enforcement.</span></li>
</ul>
<p><span style="font-weight: 400;">Built upon these key capabilities, vDefend serves as the comprehensive lateral security foundation for VCF, protecting VMs, containers, and AI workloads. The following sections will detail each of these key features.</span></p>
<h3><b>Self-Service Lateral Security with VCF Automation</b></h3>
<p><span style="font-weight: 400;">VDefend 9.1 introduces a comprehensive self-service security model that empowers Tenant Admins to manage network security directly within VCF Automation through five system-defined Security Profiles. The VPC Simplified Security feature provides one-click security for Virtual Private Clouds (VPCs) using consistent, repeatable security profiles. Tenant Admins can select a security profile for new and existing VPCs, automatically setting the default security posture and eliminating the need to manually create foundational Distributed Firewall (DFW) rules. The system-defined per-VPC DFW rules cannot be modified manually. Security policies follow a precedence order, with user-defined policies enforced before system-defined VPC security policies. This structure supports a self-service security model with automated DFW policies. In addition, this new release provides granular firewall control for both Distributed and Gateway Firewalls while enabling automated orchestration using Privileged Labels. </span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png"><img loading="lazy" decoding="async" class="wp-image-84843 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png?w=1024" alt="" width="828" height="418" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png 1102w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png?resize=300,151 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png?resize=768,387 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png?resize=1024,517 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/05/image5.png?resize=600,303 600w" sizes="auto, (max-width: 828px) 100vw, 828px" /></a></p>
<p>&nbsp;</p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png"><img loading="lazy" decoding="async" class="wp-image-84828 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png?w=1024" alt="" width="744" height="241" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png 1761w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png?resize=300,97 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png?resize=768,249 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png?resize=1024,332 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png?resize=1536,498 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image3.png?resize=600,195 600w" sizes="auto, (max-width: 744px) 100vw, 744px" /></a></p>
<p>&nbsp;</p>
<h3><b>Unified Lateral Threat Prevention for VMs and VKS Workloads</b></h3>
<p><span style="font-weight: 400;">vDefend delivers unified lateral threat prevention by extending its hypervisor-native IDS/IPS capabilities from VMs to vSphere Kubernetes Service (VKS) workloads via CNI integration. This architecture allows security teams to enable IDS/IPS at the pod level. This capability enables vDefend IDS/IPS to continuously inspect traffic, detect, and prevent threats for mixed-mode hosts (VMs and Kubernetes). </span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png"><img loading="lazy" decoding="async" class="wp-image-84827 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png?w=1024" alt="" width="744" height="309" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png 1304w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png?resize=300,125 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png?resize=768,319 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png?resize=1024,426 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image2.png?resize=600,249 600w" sizes="auto, (max-width: 744px) 100vw, 744px" /></a></p>
<h3><b>High-Performance Lateral Threat Prevention</b></h3>
<p><span style="font-weight: 400;">VMware vDefend 9.1 delivers a major performance boost with the introduction of &#8220;Turbo Mode&#8221; for Distributed IDS/IPS, which triples threat-prevention throughput from 3 Gbps to 9 Gbps per host and up to 9 Tbps within a single VCF instance. In addition, this release provides granular control over inspected traffic with exempt actions. The new exempt actions allow security admins to select which traffic to inspect and exclude trusted traffic, such as nightly backup traffic. This also improves efficiency. </span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image1.png"><img loading="lazy" decoding="async" class="wp-image-84826 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image1.png?w=1012" alt="" width="570" height="367" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image1.png 1012w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image1.png?resize=300,193 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image1.png?resize=768,495 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image1.png?resize=600,387 600w" sizes="auto, (max-width: 570px) 100vw, 570px" /></a></p>
<h3><b>Enhanced Distributed Firewall Capabilities</b></h3>
<p><span style="font-weight: 400;">The Distributed Firewall enhancements include Layer 7 (L7) visibility and simplified policy management based on Application identification. A 5x increase in Application identification, adding ~4,000 new Application IDs, provides enhanced application visibility and enables security teams to create granular firewall rules based on the application itself rather than relying solely on ports and protocols, making security enforcement simpler and more effective. Additionally, federated identity-based firewalling has been introduced to enable uniform policy enforcement across large (multi-site) deployments. </span></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png"><img loading="lazy" decoding="async" class="wp-image-84829 aligncenter" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png?w=1024" alt="" width="803" height="358" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png 1141w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png?resize=300,134 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png?resize=768,343 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png?resize=1024,457 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/image4.png?resize=600,268 600w" sizes="auto, (max-width: 803px) 100vw, 803px" /></a></p>
<h2><b>Conclusion</b></h2>
<p><span style="font-weight: 400;">The rapid growth of AI workloads and distributed infrastructure has made traditional perimeter-based security measures insufficient. This evolving threat landscape is further complicated by AI-assisted, semi-autonomous attacks and the emergence of software vulnerabilities identified by AI models, which greatly widen the attack surface. As a result, lateral security is now an essential part of a comprehensive security strategy, not just an optional addition to perimeter defenses. Security teams need controls that match the agility of their workloads, enforce policies uniformly across containers and VMs, and enable lateral security to prevent the lateral movement of threats. VMware vDefend, along with its new capabilities, enables infrastructure and security teams to implement Zero Trust lateral security to protect VCF workloads at the speed and scale the AI era demands.  </span></p>
<p><span style="font-weight: 400;">To learn more about vDefend, </span><span style="font-weight: 400;">see the links below.</span></p>
<h3><span style="font-weight: 400;">Resources</span></h3>
<ul>
<li aria-level="1"><a href="https://blogs.vmware.com/security/2026/03/vdefend-kubernetes-workloads-vcf.html"><span style="font-weight: 400;">Zero Trust Lateral Security for Kubernetes Workloads on VCF</span></a></li>
<li aria-level="1"><a href="https://blogs.vmware.com/security/2025/11/vdefend-dfw-1-2-3-4-vcf.html"><span style="font-weight: 400;">vDefend DFW 1-2-3-4: Deploy Zero Trust Microsegmentation</span></a></li>
</ul>
<ul>
<li aria-level="1"><a href="https://blogs.vmware.com/security/2026/02/zero-trust-journey-vdefend.html"><span style="font-weight: 400;">Advancing Zero Trust Private Cloud with vDefend Lateral Security</span></a></li>
</ul>
<ul>
<li aria-level="1"><a href="https://blogs.vmware.com/cloud-foundation/2026/04/29/avi-and-vdefend-for-vsphere-kubernetes-service/"><span style="font-weight: 400;">Enhance Lateral Security and Ingress Load Balancing for Kubernetes Workloads</span></a></li>
</ul>
<ul>
<li style="font-weight: 400;" aria-level="1"><a href="https://news.broadcom.com/explore/vmware-explore-2025-application-networking-and-security"><span style="font-weight: 400;">Broadcom Unveils AI-Ready Lateral Security and App Delivery Innovations</span></a></li>
</ul>
<ul>
<li aria-level="1"><a href="https://go-vmware.broadcom.com/vDefend-Webinar-Series"><span style="font-weight: 400;">vDefend Webinar Series</span></a></li>
<li><span style="font-weight: 400;"><b></b>Customer Case Studies:  </span><a href="https://www.vmware.com/resources/customers/st-johns-health-protects-private-cloud"><span style="font-weight: 400;">St. John&#8217;s Health</span></a><span style="font-weight: 400;"> | </span><a href="https://www.vmware.com/resources/customers/ussfcu-enhances-financial-wellness-with-a-vmware-private-cloud"><span style="font-weight: 400;">United States Senate Federal Credit Union</span></a><span style="font-weight: 400;"> | </span><a href="https://www.vmware.com/resources/customers/gci-closes-the-digital-divide-in-alaska-with-vmware"><span style="font-weight: 400;">GCI</span></a></li>
</ul>
<p>&nbsp;</p>
<p>&nbsp;</p><p>The post <a href="https://blogs.vmware.com/security/2026/05/vdefend-vcf-9-1-zero-trust.html">VMware vDefend for VCF 9.1: Zero Trust Lateral Security for the AI Era</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84825</post-id>	</item>
		<item>
		<title>Breaking the Ransomware Kill Chain: Why Distributed Lateral Security Is No Longer Optional</title>
		<link>https://blogs.vmware.com/security/2026/04/breaking-ransomware-kill-chain.html</link>
		
		<dc:creator><![CDATA[Umesh Mahajan]]></dc:creator>
		<pubDate>Tue, 21 Apr 2026 20:56:09 +0000</pubDate>
				<category><![CDATA[Executive Viewpoint]]></category>
		<category><![CDATA[Lateral Security]]></category>
		<category><![CDATA[ransomware prevention]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84799</guid>

					<description><![CDATA[<div><img width="300" height="153" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg 874w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?resize=300,153 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?resize=768,392 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?resize=600,306 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>This article was originally published December 2025 in:   &#160; Hugely disruptive ransomware attacks can be thwarted by distributed lateral security embedded at the private cloud level, using macro- and micro-segmentation and integrated threat detection and prevention. Ransomware attacks in 2025 have caused business operations to close for weeks and months resulting in massive financial &#8230; <a href="https://blogs.vmware.com/security/2026/04/breaking-ransomware-kill-chain.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/04/breaking-ransomware-kill-chain.html">Breaking the Ransomware Kill Chain: Why Distributed Lateral Security Is No Longer Optional</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="153" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg 874w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?resize=300,153 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?resize=768,392 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/Foundry_image1_no_copy.jpg?resize=600,306 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><em>This article was originally published December 2025 in:</em></p>
<p><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/networkworld_logo.png"><img loading="lazy" decoding="async" class="alignnone wp-image-84810" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/networkworld_logo.png?w=633" alt="" width="205" height="37" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/networkworld_logo.png 633w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/networkworld_logo.png?resize=300,54 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/networkworld_logo.png?resize=600,108 600w" sizes="auto, (max-width: 205px) 100vw, 205px" /></a><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/network_world_logo.png"> </a></p>
<p>&nbsp;</p>
<p style="text-align: center;"><em><span style="font-weight: 400;">Hugely disruptive ransomware attacks can be thwarted by distributed lateral security embedded at the private cloud level, using macro- and micro-segmentation and integrated threat detection and prevention. </span></em></p>
<p><span style="font-weight: 400;">Ransomware attacks in 2025 have caused business operations to close for weeks and months resulting in massive financial losses in organizations across the globe in sectors such as retail, manufacturing or healthcare. </span></p>
<p><span style="font-weight: 400;">These major breaches go well beyond the purview of the security team alone. They demand boardroom attention and a fundamental rethinking of enterprise defense strategies.</span></p>
<p><span style="font-weight: 400;">Much of the urgency stems from how AI has rapidly transformed the threat landscape. AI-powered autonomous attacks now probe enterprise networks with minimal human intervention, discovering thousands of potential entry points where human attackers might find only a handful. </span></p>
<p><span style="font-weight: 400;">The automated nature of these attacks means they&#8217;re finding far more vulnerabilities much faster. What happens after infiltration hasn’t changed — lateral movement, hunting for high-value assets, and initiating the ransom process. But AI makes the need for proper security hygiene even more pronounced.</span></p>
<p><span style="font-weight: 400;">The automated nature of AI-driven attacks means the enterprise needs to take a different approach to security. Traditional perimeter-based security assumes a fortress model, with strong walls that protect sensitive internal assets from external threats. But modern enterprises deploy distributed workloads, containers, and dynamic infrastructure that renders static perimeter defenses obsolete. Once attackers breach the perimeter, they can move laterally (freely) through flat (unsegmented) networks like burglars in an empty mansion.</span></p>
<h2><b>Breaking the ransomware kill chain</b></h2>
<p><span style="font-weight: 400;">Breaking the ransomware kill chain requires distributed security controls at multiple stages. During initial infiltration, intrusion prevention capabilities must operate wherever vulnerabilities exist, such as across private clouds, virtual desktop environments, and application layers. This distributed approach is critical because a single Java or Linux vulnerability might expose dozens of applications simultaneously across hundreds of servers.</span></p>
<p><span style="font-weight: 400;">Macro- and micro-segmentation is the crucial second line of defense. By creating virtual barriers at the workload and hypervisor level, organizations prevent lateral movement even after initial compromise. Rather than allowing attackers to roam freely once inside, macro- and micro-segmentation contains any threats, limiting damage and buying security teams critical response time.</span></p>
<p><span style="font-weight: 400;">However, implementation requires discipline. Organizations often mistake micro-segmentation&#8217;s ultimate goal for the first step, attempting to jump directly to granular application-level controls. The more effective path progresses systematically, guided by in-built deployment tooling in the firewall itself: assess the environment, segment shared infrastructure services, establish zone-based protections, then evolve toward application-level microsegmentation.</span></p>
<p><span style="font-weight: 400;">Network detection and response (NDR) provides the third critical capability. As attackers leave behavioral signatures while moving laterally, AI-powered integrated threat defense can correlate these indicators across the environment, identifying malicious activity before data exfiltration and encryption begin. Locking down protocols like Remote Desktop Protocol becomes essential.</span></p>
<p><span style="font-weight: 400;">The operational reality, however, is that security tool sprawl undermines even sophisticated strategies. Multiple disconnected solutions create deployment delays, policy management nightmares, and incomplete coverage across the attack chain. Organizations purchase numerous tools but deploy only a fraction and across a subset of applications, leaving dangerous gaps.</span></p>
<p><span style="font-weight: 400;">The solution lies in integrated, software-defined security that deploys at the data center private cloud level, where applications and data reside. VMware vDefend exemplifies this approach: a unified stack that provides distributed firewall capabilities for macro- and micro-segmentation with automated deployment workflows, as well as advanced threat detection and prevention that automatically extends as environments scale. By embedding security into the virtualization and Kubernetes layer with policy mobility and dynamic workload protection, organizations gain comprehensive visibility without IP address complexity or deployment delays.</span></p>
<p><span style="font-weight: 400;">Modern ransomware demands modern defenses. Not more disparate tools, but smarter architecture that breaks the kill chain before attacks succeed.</span></p>
<p><span style="font-weight: 400;">To learn more about how VMware vDefend can help your security approach meet AI-powered threats, visit <a href="https://www.vmware.com/products/security/vdefend-distributed-firewall">here</a>.</span></p><p>The post <a href="https://blogs.vmware.com/security/2026/04/breaking-ransomware-kill-chain.html">Breaking the Ransomware Kill Chain: Why Distributed Lateral Security Is No Longer Optional</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84799</post-id>	</item>
		<item>
		<title>Virtual Patching: Guarding Against a Tsunami of AI-discovered Exploits with vDefend and Avi</title>
		<link>https://blogs.vmware.com/security/2026/04/virtual-patch-guard-tsunami-ai.html</link>
		
		<dc:creator><![CDATA[Umesh Mahajan]]></dc:creator>
		<pubDate>Sat, 11 Apr 2026 19:49:58 +0000</pubDate>
				<category><![CDATA[Artificial Intelligence]]></category>
		<category><![CDATA[Modern Apps Security]]></category>
		<category><![CDATA[Network Security]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84752</guid>

					<description><![CDATA[<div><img width="300" height="200" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png 4500w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=300,200 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=768,512 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=1024,683 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=1536,1024 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=2048,1366 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=600,400 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>As the digital landscape enters the age of Artificial Intelligence, the traditional methods of securing applications are being fundamentally challenged. The emergence of advanced AI models has shifted the advantage towards attackers. With AI, even a novice attacker is now weaponized into a sophisticated hacker while operating semi-autonomously at very low cost, and unprecedented scale. &#8230; <a href="https://blogs.vmware.com/security/2026/04/virtual-patch-guard-tsunami-ai.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/04/virtual-patch-guard-tsunami-ai.html">Virtual Patching: Guarding Against a Tsunami of AI-discovered Exploits with vDefend and Avi</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="200" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png 4500w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=300,200 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=768,512 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=1024,683 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=1536,1024 1536w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=2048,1366 2048w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/04/GettyImages-1268601565.png?resize=600,400 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><span style="font-weight: 400;">As the digital landscape enters the age of Artificial Intelligence, the traditional methods of securing applications are being fundamentally challenged. The emergence of advanced AI models has shifted the advantage towards attackers. With AI, even a novice attacker is now weaponized into a sophisticated hacker while operating semi-autonomously at very low cost, and unprecedented scale. Imagine the massive damage that ransomware gangs and/or nation-state actors could do with these cyber weapons.  In recent times, ransomware attacks have led to business operations going offline for weeks and months, resulting in financial losses in hundreds of millions of dollars. To maintain a cyber resilient posture, organizations must move beyond reactive security and embrace a proactive defense-in-depth strategy centered on lateral security and virtual patching.</span></p>
<h2><b>AI-discovered Tsunami of Exploits</b></h2>
<p><span style="font-weight: 400;">Frontier AI models have the intelligence to identify unknown (zero day) software vulnerabilities (bugs) and find ways to exploit them faster than ever before. Attackers can leverage these exploits to infiltrate digital enterprises, propagate laterally, hopping and hunting, to find high value assets for ransom or for stealing secrets. They can initiate widespread, volumetric and/or targeted attacks semi-autonomously – leading to an exponential increase in the attack surface. “Security through obscurity&#8221; is no longer a viable cyber security strategy.</span></p>
<p><span style="font-weight: 400;">If enterprises can quickly patch software vulnerabilities, they can certainly reduce the risk of a breach and/or its spread. However, this is an extremely time consuming and resource intensive endeavor. There are thousands of software tools and apps, each with varied software versions, deployed on different types of hardware and operating systems and spread across multiple data centers. In larger organizations, “race to patch” can take weeks to months to roll out patches enterprise wide, leaving the organization exposed to infiltration, ransom and potentially business disruption.</span></p>
<p><span style="font-weight: 400;">To help quickly protect against this tsunami of exploits unleashed against workloads &amp; apps and to buy down risk, enterprises need to focus on two key defenses for their private cloud workloads:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Enable virtual patching using intrusion prevention systems and web application firewall</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Restrict propagation of attacks with lateral segmentation</span></li>
</ul>
<h2><b>What is Virtual Patching?</b></h2>
<p><span style="font-weight: 400;">Virtual patching is a vulnerability-shielding tactic that protects assets by implementing a minimal layer of security policies at the network or application delivery level, front ending that asset. These measures intercept and block exploit attempts before they can reach the vulnerable software, effectively &#8220;patching&#8221; the flaw in the communication path rather than the software itself. </span></p>
<h3><b>Key Benefits of Virtual Patching</b></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Application availability: </b><span style="font-weight: 400;">Ensures that applications/assets are available while the risks are mitigated</span></li>
<li style="font-weight: 400;" aria-level="1"><b>No code changes:</b><span style="font-weight: 400;"> It protects applications without requiring deployment of updated software/patches. Software patches can introduce regressions: this approach eliminates that risk</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Targeted signatures:</b><span style="font-weight: 400;"> Reduces the risk of false positives and performance impact</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Zero-Day Protection:</b><span style="font-weight: 400;"> Provides a rapid response to vulnerabilities for which no official patch yet exists.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Legacy Support:</b><span style="font-weight: 400;"> Shields older, unsupported systems that are still critical to business operations. Patches may not even exist for legacy applications</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Buys Time:</b><span style="font-weight: 400;"> Grants security teams the necessary cycles to test and deploy permanent vendor patches without remaining exposed</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Helps with Compliance</b><span style="font-weight: 400;">: Many regulations such as PCI-DSS and HIPAA, require timely deployment of security controls to remain compliant</span></li>
</ul>
<h3><b>vDefend Distributed IDPS: Hypervisor-embedded Virtual Patching </b></h3>
<p><span style="font-weight: 400;">VMware vDefend provides a revolutionary approach to virtual patching of workloads by integrating security directly into the </span><a href="https://www.vmware.com/products/cloud-infrastructure/vmware-cloud-foundation"><span style="font-weight: 400;">VMware Cloud Foundation</span></a><span style="font-weight: 400;"> (VCF) hypervisor fabric. The </span><a href="https://www.vmware.com/products/security/vdefend-advanced-threat-prevention"><span style="font-weight: 400;">vDefend IDPS</span></a><span style="font-weight: 400;"> (Intrusion Detection and Prevention System) is applied directly to the vNIC of every workload, enabling deep, granular inspection of application traffic (every packet) moving across the VCF private cloud, specifically targeting network-layer exploits and lateral movements.</span></p>
<h3><b>How vDefend IDPS Enables Virtual Patching</b></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Hypervisor-Integrated Inspection:</b><span style="font-weight: 400;"> vDefend’s Distributed IDPS inspects network traffic at the vNIC of every VCF workload. This ensures unpatched servers cannot be exploited by attacks originating from the outside or from inside the network. </span></li>
<li style="font-weight: 400;" aria-level="1"><b>Automated dynamic policies: </b><span style="font-weight: 400;">Run a vulnerability scan to identify workloads, apply appropriate tags and create a virtual patching policy with a limited set of IDPS signatures. As new vulnerable workloads are identified and tagged, the policies are applied automatically and vulnerable workloads get immediate protection.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>East-West Security:</b><span style="font-weight: 400;"> IDPS prevents attackers from exploiting vulnerabilities to move laterally within the environment (and eventually compromising high-value assets).</span></li>
</ul>
<h3><b>Examples of Vulnerabilities Protection</b></h3>
<ul>
<li aria-level="1"><b>Moveit Transfer Auth Bypass </b><span style="font-weight: 400;">(</span><a href="https://nvd.nist.gov/vuln/detail/cve-2024-5806"><span style="font-weight: 400;">CVE-2024-5806</span></a><span style="font-weight: 400;">): This flaw in the SFTP module of Moveit Transfer allowed attackers to bypass authentication and steal files without a password. vDefend can detect the &#8220;insufficient validation&#8221; logic patterns during the initial connection phase and stop the attack in it’s tracks. </span></li>
</ul>
<ul>
<li aria-level="1"><b>Ni8mare </b><span style="font-weight: 400;">(</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21858"><span style="font-weight: 400;">CVE-2026-21858</span></a><span style="font-weight: 400;">): This unauthenticated RCE flaw in the n8n automation platform allows attackers to achieve full system takeover via &#8220;Content-Type confusion.&#8221; vDefend identifies these malformed JSON payloads and malicious header mismatches, blocking the exploit before an attacker can hijack internal workflows to move laterally through the data center.</span></li>
</ul>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Log4Shell (</b><a href="https://nvd.nist.gov/vuln/detail/cve-2021-44228"><span style="font-weight: 400;">CVE-2021-44228</span></a><b>):</b><span style="font-weight: 400;"> vDefend IDPS can detect and prevent </span><span style="font-weight: 400;">against attempts at </span><a href="https://knowledge.broadcom.com/external/article?legacyId=87156"><span style="font-weight: 400;">exploiting</span></a><span style="font-weight: 400;"> the Log4shell vulnerability. </span><span style="font-weight: 400;">This exploit, residing in the Java Naming and Directory Interface (JNDI), can download malicious scripts and perform remote code execution, allowing full control of the targeted system. (</span><a href="https://www.youtube.com/watch?v=YSB2_2O2FpQ"><span style="font-weight: 400;">Demo: Protecting against Log4Shell with VMware vDefend ATP</span></a><span style="font-weight: 400;">)</span></li>
</ul>
<h3><b>The vDefend Advantage:</b><span style="font-weight: 400;"> What makes vDefend IDPS powerful for this use case is its architectural advantage, signature strategy, and operational simplicity. </span></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Speed matters in the era of AI-driven threats. vDefend&#8217;s built-in closed-loop security architecture — through integration with the VCF private cloud platform — delivers detection as well as rapid mitigation, thus dramatically reducing attacker dwell time.</span><span style="font-weight: 400;"> </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">vDefend IDPS supports IDPS signatures that are frequently updated (multiple times a day), ensuring protection against the latest global threats. </span><span style="font-weight: 400;">Broadcom has a threat intelligence team that actively analyzes new exploits, creates signatures, and updates the signature bundles (see </span><a href="https://portal.securityti.vmware.com/#/app/ids-signatures"><span style="font-weight: 400;">IDPS signature portal</span></a><span style="font-weight: 400;">)</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Furthermore, IDPS supports </span><i><span style="font-weight: 400;">custom IDPS signatures</span></i><span style="font-weight: 400;">: customers can import trusted signatures from third-parties or develop in-house to virtually patch their applications. This provides a truly bespoke security posture.</span></li>
</ul>
<h3><b>vDefend Distributed Firewall: Restrict Unauthorized Lateral Propagation</b></h3>
<p><span style="font-weight: 400;">To further restrict lateral propagation of threats, vDefend also provides a high-performance hypervisor-embedded Layer-7 </span><a href="https://www.vmware.com/products/security/vdefend-distributed-firewall"><span style="font-weight: 400;">Distributed Firewall</span></a><span style="font-weight: 400;"> (DFW). It allows comprehensive lateral segmentation of VCF workloads through highly streamlined context (or tag) based security policies. Lateral segmentation includes both macro and micro-segmentation, applied to ensure trusted (least-privileged) access to infrastructure services, environments (or zones), and applications. DFW is fully scale-out, eliminates traffic tromboning and the need for network changes (unlike traditional firewalls), and preserves the segmentation posture during vMotion events. It also includes a built-in prescriptive deployment tool, DFW 1-2-3-4 (</span><a href="https://blogs.vmware.com/security/2025/11/vdefend-dfw-1-2-3-4-vcf.html"><span style="font-weight: 400;">blog</span></a><span style="font-weight: 400;">), enabling rapid self-deployment across all workloads in as little as a few weeks.</span></p>
<h3><strong>Avi Web Application Firewall: Virtual Patching for Web Applications</strong></h3>
<p><span style="font-weight: 400;">While vDefend secures the internal network, the </span><a href="https://www.vmware.com/products/cloud-infrastructure/advanced-services/avi-load-balancer"><span style="font-weight: 400;">Avi Web Application Firewall (WAF)</span></a><span style="font-weight: 400;"> acts as the first line of defense for web-facing applications, providing virtual patching at the web layer.</span></p>
<h3><strong>How Avi WAF Prevents Exploitation</strong></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Edge Defense:</b><span style="font-weight: 400;"> Avi WAF analyzes incoming north-south traffic, identifying and neutralizing </span><a href="https://owasp.org/Top10/2025/#top-102025-list"><span style="font-weight: 400;">OWASP Top 10</span></a><span style="font-weight: 400;"> threats before they reach the application.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Protocol-Aware Inspection:</b><span style="font-weight: 400;"> Its robust HTTP/HTML parser understands complex protocol features, ensuring that even obfuscated exploit attempts are caught within the application payload.</span></li>
</ul>
<h3><strong>Examples of Vulnerabilities Protection</strong></h3>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>SQL Injection (SQLi):</b><span style="font-weight: 400;"> Avi WAF virtually patches vulnerable databases by stripping malicious SQL commands from web entry fields. An example is </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31044"><span style="font-weight: 400;">CVE-2025-31044</span></a><span style="font-weight: 400;"> in the Premium SEO Pack plugin of WordPress. Avi uses a pipeline-based security model to provide protection against SQLi at different stages of the incoming traffic.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) :</b><span style="font-weight: 400;"> Avi WAF’s built-in CSRF (Cross-Site Request Forgery Protection) prevents attackers from injecting client-side scripts into web pages by sanitizing incoming requests. For example, Avi protects against the MCP inspector tool vulnerability (</span><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49596"><span style="font-weight: 400;">CVE-2025-49596</span></a><span style="font-weight: 400;">) that exposes a new class of browser-based attacks against AI developer tools. </span></li>
<li style="font-weight: 400;" aria-level="1"><b>React2shell (</b><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182"><b>CVE-2025-55182</b></a><b>)</b><b>:</b> <span style="font-weight: 400;">Avi WAF blocks Remote Code Execution (RCE) attempts like Command Injection, Application Language Specific attacks, and also blocks attempts to include remote files (RFI) or local system files (LFI) that could lead to attackers to execute arbitrary commands on application serve</span><span style="font-weight: 400;">r.</span></li>
</ul>
<p><strong>Avi WAF for Vulnerability Scanner to further Virtual Patching</strong><span style="font-weight: 400;"><strong>:</strong> Avi WAF provides an inbuilt SDK that can import Dynamic Application Security Testing (DAST) scanner results to construct the customized WAF policy to protect the application from security threats found by the scanner. Avi WAF supports </span><a href="https://www.qualys.com/apps/web-app-scanning/"><span style="font-weight: 400;">Qualys Web App Scanning</span></a><span style="font-weight: 400;"> and </span><a href="https://www.zaproxy.org/"><span style="font-weight: 400;">OWASP ZAP Attack Proxy</span></a><span style="font-weight: 400;"> DAST scanner results</span><span style="font-weight: 400;">.</span></p>
<p><b>The Avi Advantage:</b><span style="font-weight: 400;">  Key differentiators for Avi WAF are its software-defined architecture, scale-out and full access to the Avi customer base.</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Unlike alternative WAF solutions that require a separate, expensive license, Avi WAF is available to all Avi customers as part of the Avi license. Essentially every Avi Load Balancer customer also has the built-in capability to secure their web applications by default. </span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Avi is also fully integrated with VCF, thus delivering plug-and-play operational experience and self-service load balancing and WAF – for both VM and Kubernetes (</span><a href="https://www.vmware.com/products/cloud-infrastructure/vsphere-kubernetes-service"><span style="font-weight: 400;">VMware Kubernetes Service</span></a><span style="font-weight: 400;"> – VKS) workloads.</span></li>
</ul>
<h2><b>Conclusion</b></h2>
<p><span style="font-weight: 400;">In the era of AI-accelerated threat landscape, the &#8220;race to patch&#8221; has reached a breaking point. Organizations can no longer rely solely on eventual roll-out of code updates to stay secure. By leveraging </span><b>vDefend Distributed IDPS</b><span style="font-weight: 400;"> for lateral virtual patching, </span><b>vDefend DFW</b><span style="font-weight: 400;"> for lateral segmentation and </span><b>Avi WAF</b><span style="font-weight: 400;"> for web application security, enterprises can implement a comprehensive private cloud cyber defense strategy. This multi-layered approach provides an immediate and comprehensive defense that blocks hackers from exploiting vulnerabilities, buying the IT team the critical time needed to maintain long-term application integrity.</span></p>
<h3>To learn more about how to protect your environment from AI exploits, watch the following videos:</h3>
<p><a href="https://youtu.be/S_ChnXQQp7k">Multi-Layer Defense in the AI Era</a></p>
<p><a href="https://youtu.be/WTr8B0jzsgQ">Defeating AI-Accelerated Exploit Chains with vDefend Virtual Patching</a></p><p>The post <a href="https://blogs.vmware.com/security/2026/04/virtual-patch-guard-tsunami-ai.html">Virtual Patching: Guarding Against a Tsunami of AI-discovered Exploits with vDefend and Avi</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84752</post-id>	</item>
		<item>
		<title>VMware vDefend: Zero Trust Lateral Security for Kubernetes Workloads on VCF</title>
		<link>https://blogs.vmware.com/security/2026/03/vdefend-kubernetes-workloads-vcf.html</link>
		
		<dc:creator><![CDATA[Madhukar Krishnarao]]></dc:creator>
		<pubDate>Tue, 10 Mar 2026 17:32:12 +0000</pubDate>
				<category><![CDATA[Advanced Threat Prevention]]></category>
		<category><![CDATA[Microsegmentation]]></category>
		<category><![CDATA[Network Security]]></category>
		<guid isPermaLink="false">https://blogs.vmware.com/security/?p=84694</guid>

					<description><![CDATA[<div><img width="300" height="150" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg 640w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg?resize=300,150 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg?resize=600,301 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div>
<p>In a cloud-native environment, Kubernetes-based containerized orchestration has brought developer agility &#8211; but it has also fundamentally changed the security paradigm. Traditional “castle-and-moat” security designs that rely on a perimeter firewall are no longer enough to protect modern workloads. Once an attacker breaches that outer shell, the flat network architecture common in many Kubernetes environments &#8230; <a href="https://blogs.vmware.com/security/2026/03/vdefend-kubernetes-workloads-vcf.html">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/security/2026/03/vdefend-kubernetes-workloads-vcf.html">VMware vDefend: Zero Trust Lateral Security for Kubernetes Workloads on VCF</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div><img width="300" height="150" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg?w=300" class="attachment-medium size-medium wp-post-image" alt="" style="margin-bottom: 10px;" decoding="async" loading="lazy" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg 640w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg?resize=300,150 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Getty-2206613255.jpg?resize=600,301 600w" sizes="auto, (max-width: 300px) 100vw, 300px" /></div><p><span style="font-weight: 400;">In a cloud-native environment, Kubernetes-based containerized orchestration has brought developer agility &#8211; but it has also fundamentally changed the security paradigm. Traditional “castle-and-moat” security designs that rely on a perimeter firewall are no longer enough to protect modern workloads. Once an attacker breaches that outer shell, the flat network architecture common in many </span><a href="https://www.cncf.io/blog/2025/04/22/these-kubernetes-mistakes-will-make-you-an-easy-target-for-hackers/"><span style="font-weight: 400;">Kubernetes environments</span></a><span style="font-weight: 400;"> allows them to move laterally with ease, potentially compromising many applications in their hunt for high-value assets to ransom. The cyber landscape is further </span><span style="font-weight: 400;">exacerbated by recent cyberattacks that have halted business operations for weeks and months, causing massive financial losses (hundreds of millions of dollars or more) and the </span><span style="font-weight: 400;">emergence of </span><a href="https://www.pwc.com/us/en/services/consulting/cybersecurity-risk-regulatory/library/ai-orchestrated-cyberattacks.html"><span style="font-weight: 400;">AI-driven autonomous attacks</span></a><span style="font-weight: 400;">.</span></p>
<p><span style="font-weight: 400;">Bridging this lateral security gap with VMware vDefend is crucial for organizations leveraging vSphere Kubernetes Service (VKS) within VMware Cloud Foundation (VCF). The fact that vDefend is fully integrated with VKS and completely plug-and-play with VCF makes a comprehensive rollout of Zero Trust lateral protection across all VKS clusters operationally simple and fast. Businesses can finally implement a true Zero Trust security model consistently across Virtual Machines and Containers – the same policy model, the same management console and APIs, the same troubleshooting tools. The powerful combination of vDefend with VKS Clusters decouples security policy from static, ephemeral IP addresses and instead uses workload-based identity to enforce granular protection.</span></p>
<p><span style="font-weight: 400;">In a typical Kubernetes cluster, network identity is fleeting. Containers are designed to be short-lived; when a pod is terminated, and a new one is created, a completely different IP address is assigned. This “ephemeral” nature makes traditional IP-based firewall rules obsolete almost instantly, leading to administrative overhead or, worse, massive security holes.</span></p>
<p><span style="font-weight: 400;">The integration of VMware vDefend and vSphere Kubernetes Service (VKS) solves this by decoupling security from the networking layer. Instead of relying on static IPs, vDefend uses </span><a href="https://antrea.io/"><span style="font-weight: 400;">Antrea CNI</span></a><span style="font-weight: 400;">, the default CNI with VKS, to enforce context-aware policies based on logical metadata &#8211; such as labels applied to namespaces, services, and pods. Because the security policy is tied to the workload’s identity rather than its IP address, the protection follows the Pod automatically, even as it scales or is recreated on a different node. Furthermore, this enforcement occurs at the immediate point of origin—the Pod interface for containerized workloads and the vNIC for Virtual Machines within the Hypervisor. This ensures that security is applied at the &#8216;first hop,&#8217; neutralizing threats before they ever traverse the physical or virtual network. </span></p>
<h3>Unified Management: One Policy to Rule Them All</h3>
<p><span style="font-weight: 400;">Operational silos, where separate security stacks have to be implemented for virtual machines and Kubernetes clusters, are a major hurdle in modern infrastructure, often leading to inconsistent protection and blind spots. vDefend addresses this by providing a unified security management solution for VMs and Kubernetes (VKS) workloads through a single pane of glass within VCF. This enables security administrators to define a global security posture that is consistently applied across the entire Supervisor cluster and all guest VKS clusters, without treating the VKS clusters as opaque entities.</span></p>
<p style="text-align: center;"><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png"><img loading="lazy" decoding="async" class="alignnone wp-image-84695" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png?w=1024" alt="" width="841" height="520" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png 1200w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png?resize=300,186 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png?resize=768,475 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png?resize=1024,633 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image7.png?resize=600,371 600w" sizes="auto, (max-width: 841px) 100vw, 841px" /></a></p>
<h2></h2>
<h2>Bridging the Gap: Securing the “In-Between”</h2>
<p><span style="font-weight: 400;">The most critical vulnerability in modern architecture often lies at the intersection of different workload types. A typical application might host its frontend in a containerized VKS pod while keeping its mission-critical database on a traditional virtual machine. Traditionally, these two worlds lived in separate security boundaries, making inter-workload traffic difficult to monitor and secure. VMware vDefend bridges this critical gap. Because it is natively integrated into the ESXi hypervisor, vDefend can inspect traffic closest to the source, as it moves between a container and a VM &#8211; even if they are on the same host. This cross-workload security ensures that the “mixed-mode” applications are protected by a continuous zero-trust boundary, stopping lateral movements regardless of whether the threat is hopping from a pod to a VM or vice versa.</span></p>
<p style="text-align: center;"><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png"><img loading="lazy" decoding="async" class="alignnone wp-image-84696" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png?w=1024" alt="" width="818" height="404" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png 1200w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png?resize=300,148 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png?resize=768,380 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png?resize=1024,506 1024w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image11.png?resize=600,297 600w" sizes="auto, (max-width: 818px) 100vw, 818px" /></a></p>
<h2>Control for Security Admins and Freedom for App Developers</h2>
<p><span style="font-weight: 400;">In modern enterprises with Kubernetes workloads, security often becomes a shared responsibility between centralized security teams and application owners. While security teams typically define the organization&#8217;s overarching security model, application owners frequently control the security policies for their specific applications. While this ops model offers flexibility, it could create security gaps. vDefend addresses this by enabling security administrators and application owners to co-own container security policies through a central management view. Security administrators can control cluster-level firewall policies (ingress and egress traffic for a VKS cluster) to focus on environmental and infrastructure security. By utilizing vDefend&#8217;s distinct firewall categories, they can ensure these essential policies are always enforced first. Meanwhile, application owners retain complete autonomy to define application-tier Kubernetes </span><span style="font-weight: 400;">networkPolicies</span><span style="font-weight: 400;"> without requiring explicit approval from security administrators. This collaborative approach ensures comprehensive protection across the board.</span></p>
<p style="text-align: center;"><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image6.png"><img loading="lazy" decoding="async" class="alignnone wp-image-84697" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image6.png?w=800" alt="" width="828" height="376" srcset="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image6.png 800w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image6.png?resize=300,136 300w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image6.png?resize=768,348 768w, https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/image6.png?resize=600,272 600w" sizes="auto, (max-width: 828px) 100vw, 828px" /></a></p>
<p><span style="font-weight: 400;">To truly understand the power of a unified security stack, it helps to look at how it handles real-world threats. By applying vDefend to VKS, administrators can move beyond broad “allow-all” rules and implement surgical precision in the security posture.</span></p>
<ul>
<li aria-level="1"><b>Quarantining a Compromised Workload</b></li>
</ul>
<p style="padding-left: 40px;"><span style="font-weight: 400;"><span style="font-weight: 400;">O</span></span><span style="font-size: 1rem;">ne of the most important scenarios for a DevSecOps team is a “malicious-pod” &#8211; a container that has been compromised and is now attempting to scan the network for vulnerabilities and exfiltrate data. In a standard Kubernetes setup, this pod might have a “flat” path to every other service in the cluster. With vDefend firewall policies, you can execute a “Quarantine” strategy. By applying specific tags (e.g., quarantine = malicious) to the suspected pod, a high-precedence Emergency Category policy is instantly triggered. This policy overrides all other existing rules, immediately dropping all inbound and outbound traffic to the pod except for a secured connection to a “forensic pod” or a “jump host” for investigation. This drastically reduces the blast radius of the breach, stopping lateral movement before it starts.</span></p>
<ul>
<li aria-level="1"><b>Hardening External Egress Traffic</b></li>
</ul>
<p style="padding-left: 40px;"><span style="font-weight: 400;">In a Zero Trust environment, what goes <i>out</i> of your VKS cluster is just as important as what comes <i>in</i>. Many modern attacks, such as the Log4Shell exploit, rely on compromised workloads contacting malicious command-and-control systems. Protecting egress traffic in VKS is uniquely challenging because IPs are typically lost behind a generic Source Network Address Translation (SNAT) at the node. The solution is to leverage Antrea Egress to provide a stable, predictable identity for outbound traffic. By associating specific pods with an Egress IP, you can create granular vDefend firewall rules that allow only a specific production application to talk to an external database while blocking the rest of the cluster. This ensures that even if a workload is compromised, it cannot reach unauthorized external endpoints.</span></p>
<h2>Future-Proofing with VCF and vDefend</h2>
<p><span style="font-weight: 400;">By deeply integrating vDefend with VKS, the platform eliminates the traditional trade-off between developer agility and enterprise security.</span></p>
<p><span style="font-weight: 400;">Key Benefits for VCF Customers:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Zero-Trust by Default:</b><span style="font-weight: 400;"> Organizations can now enforce a granular, Zero Trust model that covers the entire stack – from legacy virtual machines to ephemeral Kubernetes pods. This intrinsic security model stops ransomware and other sophisticated threats from moving laterally across your environment.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Operational Simplicity:</b><span style="font-weight: 400;"> VCF and vDefend introduce a “single pane of glass” for policy management. Instead of juggling fragmented tools for container and VM security, administrators use a unified operational model that reduces the learning curve and eliminates manual configuration drift.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Accelerated Time-to-Market:</b><span style="font-weight: 400;"> With self-service capabilities and automated policy orchestration, developers can spin up secured applications in minutes rather than months. Security is applied as soon as a workload is provisioned – security at the speed of apps, ensuring compliance from the very first packet without requiring tickets to multiple infrastructure teams.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Deep Insights and Troubleshooting:</b><span style="font-weight: 400;"> The vDefend integration with VCF and VKS provides unparalleled insights into VM and container traffic flows. Features like Antrea Traceflow allow teams to synthetic-test their network paths, ensuring that every firewall rule functions as intended before an issue escalates.</span></li>
</ul>
<h2>Making VKS clusters vDefend Ready – video demo</h2>
<p><span style="font-weight: 400;">Safeguarding your containerized workloads on VKS with vDefend shouldn’t be a complex hurdle. This video demonstrates just how simple it is to make the VKS cluster vDefend ready. By following the streamlined process, you can make your clusters vDefend-ready in minutes, unlocking powerful macro and microsegmentation capabilities. Whether you are managing existing deployments or spinning up new environments, this tutorial shows how remarkably easy it is to have your VKS cluster ready for vDefend.</span></p>
<div style="width: 1280px;" class="wp-video"><!--[if lt IE 9]><script>document.createElement('video');</script><![endif]-->
<video class="wp-video-shortcode" id="video-84694-1" width="1280" height="720" preload="metadata" controls="controls"><source type="video/mp4" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Register-VKS-cluster-with-NSX-to-make-it-vDefend-ready.mp4?_=1" /><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Register-VKS-cluster-with-NSX-to-make-it-vDefend-ready.mp4">https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Register-VKS-cluster-with-NSX-to-make-it-vDefend-ready.mp4</a></video></div>
<p>&nbsp;</p>
<p><span style="font-weight: 400;">Core insights from the video:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Seamless Integration: Learn how the registration process acts as the “handshake” between your VKS cluster and vDefend</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Operational Simplicity: See firsthand that making a VKS cluster vDefend ready doesn’t require complex coding; it&#8217;s a straightforward workflow within the management console</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Automated Discovery: Discover how VKS namespaces, pods, and services are automatically recognized, enabling set-and-forget policies that scale as your cluster grows</span></li>
</ul>
<h2>Securing Modern Applications with VMware vDefend – video demo</h2>
<p><span style="font-weight: 400;">Here is a video walkthrough of the simple steps for protecting modern applications deployed across a virtual machine environment and a VKS cluster. It showcases how robust security policies can be implemented in vDefend to prevent lateral movement between services in VKS clusters and also easily block unauthorized access to external systems from the VKS cluster.</span></p>
<div style="width: 1280px;" class="wp-video"><video class="wp-video-shortcode" id="video-84694-2" width="1280" height="720" preload="metadata" controls="controls"><source type="video/mp4" src="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Securing-Modern-Applications-with-VMware-vDefend-and-Antrea-1.mp4?_=2" /><a href="https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Securing-Modern-Applications-with-VMware-vDefend-and-Antrea-1.mp4">https://blogs.vmware.com/security/wp-content/uploads/sites/26/2026/02/Securing-Modern-Applications-with-VMware-vDefend-and-Antrea-1.mp4</a></video></div>
<p>&nbsp;</p>
<p><span style="font-weight: 400;">Core insights from the video:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Simplified Management: See how a single pane of glass with VKS and vDefend allows administrators to quickly and efficiently manage policies for both containerized workloads and virtual machine workloads</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Unified Security Policy: Understand how registering a VKS cluster allows you to apply consistent firewall rules across both traditional virtual machines and modern containerized workloads</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">Egress Security: As mentioned above, Antrea Egress provides a stable, predictable identity for outbound traffic. This can be used to create granular vDefend firewall rules to allow only a specific service to communicate with an external database</span></li>
</ul>
<h2>vDefend is Key to a Secure and Agile Private Cloud</h2>
<p><span style="font-weight: 400;">By adopting the models described above, VCF operators who deploy vDefend are building resilient, scalable, and automated security foundations. As applications continue to evolve into complex webs of containers and VMs, having a unified security layer is no longer just a “best practice” &#8211; it is the key to maintaining a secure and agile private cloud.</span></p>
<p>&nbsp;</p>
<h3>Further Reading:</h3>
<p><span style="font-weight: 400;">Check out the detailed</span> <a href="https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/design-library-for-vdefend/index/securing-vks.html"><span style="font-weight: 400;">Securing vSphere Supervisor and VKS with vDefend</span></a><span style="font-weight: 400;"> reference design, which serves as both an architectural blueprint and a practical implementation handbook for using VMware vDefend security solutions. It offers essential design insights and security recommendations to enhance the protection of vSphere Supervisor and the mixed-form-factor workloads running on it: Virtual Machines, vSphere Pods, and VKS.</span></p>
<p>&nbsp;</p><p>The post <a href="https://blogs.vmware.com/security/2026/03/vdefend-kubernetes-workloads-vcf.html">VMware vDefend: Zero Trust Lateral Security for Kubernetes Workloads on VCF</a> appeared first on <a href="https://blogs.vmware.com/security">VMware Security Blog</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">84694</post-id>	</item>
	</channel>
</rss>
