Broadcom released security-centric updates to VMware vDefend and VMware Avi Load Balancer in a salvo against frontier AI model threats.
The vDefend Security Services Platform (SSP) now includes the three-step workflow of intrusion detection and prevention system (IDPS), network traffic analysis (NTA), and network detection and response (NDR).
Dubbed Accelerated Advanced Threat Prevention (ATP) with vDefend 1-2-3, the service works in conjunction with the platform’s distributed firewall (DFW) for deeper workload-level visibility. According to Broadcom, DFW throughput is upped by 129% to 22 Gb/s on 25G network interface card (NIC) servers, and 75 Gb/s on 100G NIC servers with a 241% bump, achieving up to 75 Tb/s scale-out performance per VMware Cloud Foundation (VCF) instance.
Another addition is the vDefend and Avi Conversion Tool (vACT), which automatically converts existing firewall rules and configurations directly into native vDefend policies. On top of this, VMware vDefend was updated with on-premises malware prevention, allowing for static and dynamic artifacts analysis within the local network, plus comprehensive support in air-gapped environments.
Finally, vDefend SSP can now run as a two-server cluster instead of requiring three physical servers, potentially helping to lower infrastructure costs for enterprises.
API armor in Avi Load Balancer #
Broadcom flagged Akamai research that nearly 87% of global organizations suffered an API security incident in 2025, with Astra Security claiming global enterprise losses of up to $186 billion annually.
As such, VMware was enhanced with native API protection for virtual machines (VMs), vSphere Kubernetes Services (VKS), and AI-based workloads. Broadcom said the combination of web application firewall (WAF) and API protection (WAAP) shields vulnerable APIs while reducing the high cost and complexity of fragmented IT infrastructure, with up to an 88% increase in scale-out throughput to 12.25 Tb/s per controller instance.
Avi WAAP, as the function is known, is positioned directly inline of the application traffic to automatically discover all API traffic without requiring manual developer entry.
The stack integrates WAF with distributed denial of service (DDoS) protection, advanced bot management, layer-seven (L7) rate limiting, IP reputation filtering, and secure socket layer/transport layer security (SSL/TLS) termination. Embedded zero-day protection leverages closed-loop analytics and AI-assisted application learning to help Avi establish “a positive security model that validates known good behavior in real time.”
It also automatically categorizes every discovered endpoint into four categories: shadow, orphan, zombie, and active (SOZA), while applying granular policy enforcement per API centered around custom rate limiting, authentication requirements, HTTP security policies and specific WAF rules, including Swagger/OpenAPI specifications.
Broadcom positioned both sets of updates to vDefend and Avi Load Balancer as a response to the recent Hugging Face breach, which saw OpenAI models run amok on its systems.
“As AI-fueled cyberattacks and vulnerability exploits redefine the threat landscape, a fragmented security approach is no longer an option,” Umesh Mahajan, VP and GM for Broadcom's Application Networking and Security Division, explained. “We are giving enterprise customers the protection, performance, and automation they need to defend their application infrastructure at scale.”