Kubernetes Lateral Security VCF Security VMware Explore

VMware vDefend Sessions at VMware Explore 2026

VMware Explore returns to the Venetian Convention and Expo Center in Las Vegas from August 31 – Sep. 03, 2026. Step into the next generation of enterprise infrastructure and witness firsthand how VMware vDefend delivers comprehensive lateral security for VMware Cloud Foundation in the Agentic AI era.

Gain expertise from in-person discussions, presentations, and live demos, learning what vDefend offers in today’s dynamic and rapidly changing AI-era landscape. Add the sessions below to your schedule for this year’s event.

Executive Highlight Session

Umesh Mahajan at VMware Explore 2025

Operationalizing Cyber Defense and App Resilience for the Agentic AI Era [SECB1789LV]
Tuesday, Sep 1  2:00 PM – 2:45 PM PDT

Digital IT is adopting agentic AI to help businesses further differentiate and boost productivity. AI is also the cause of attack surface explosion, as bad actors armed with the same AI models autonomously infiltrate enterprises. Infrastructure operators need new innovations that accelerate their AI journey, while ensuring app resilience and complete cyber lockdown of large language models (LLMs), agents, data stores, and MCP services. Join Umesh Mahajan, GM of Application Networking and Security (ANS), Broadcom, to learn how IT is consuming lateral security and app delivery for AI and non-AI workloads. The session will cover operational best practices to implement Zero Trust and app resilience Day 1 for VMware Cloud Foundation® (VCF) 9.1 and private AI, leveraging new innovations in VMware® vDefend™ and VMware® Avi™ Load Balancer. The deployment journey will focus on rapid rollout to buy-down risk while ensuring app availability, investment protection, and consistent operations of VMs, VMware vSphere® Kubernetes Service, and agentic AI workloads.

Umesh Mahajan, VP & GM, Application Networking and Security, Broadcom
Prashant Gandhi, Head of Products, Application Networking and Security, Broadcom

People’s Choice Award Winner – Breakout Session

Enforcing Zero Trust for Apps Across Multi-Cluster VMware vSphere Kubernetes Service [SECB1079LV]
Tuesday, Sep 1  10:15 AM – 11:00 AM PDT

As VMware vSphere® Kubernetes Service (VMware VKS) becomes the go-to runtime for running modern applications and especially AI applications on VMware Cloud Foundation® (VCF), how do you enforce strict Zero Trust for workloads across multiple Kubernetes clusters and VMs? In this session, we will show how SecOps can define a central “security taxonomy” via labels, and how developers deploy apps that automatically consume those policies. We will look at how VMware® vDefend™ and Antrea CNI work together to enforce microsegmentation across VKS clusters from a single control plane. We will cover: • Building a label-based taxonomy for Kubernetes apps • Enforcing Zero Trust with vDefend and Antrea across L4 • Protecting L7 with end-to-end mTLS and WAF using Istio and VMware® Avi™ • Ensuring bad actors cannot bypass global security • Automating policy rollouts via Terraform. Finally, we will wrap up with a demo showing this entire automated workflow in action.

Chris McCain, Field CTO, Broadcom
Niran Evenchen, Principal Solution Architect, Broadcom

Breakout Sessions

Lateral Security Simplified: The VMware vDefend Distributed Firewall 1-2-3-4 Security Journey [SECB1247LV]
Monday, Aug 31  9:00 AM – 9:45 AM PDT

Stopping lateral movement within the data center is critical, yet many organizations struggle with the complexity of mapping and securing east-west traffic. The VMware vDefend Security Journey provides a prescriptive, data-driven workflow designed to simplify lateral security for VMware Cloud Foundation®. In this session, we break down the “1-2-3-4” deployment framework to help you move from zero visibility to a fully hardened environment. We will walk through the four essential stages: protecting critical shared services, segmenting broad environments, securing specific application tiers, and achieving final lockdown. Whether you are starting from scratch or refining your firewall, you will leave with a practical roadmap to eliminate lateral threats.

Catherine Fan, Technology Product Manager, Broadcom
Andrew Hrycaj, Technical Product Manager, Broadcom

Demystifying vDefend Distributed Security within VMware Cloud Foundation [SECB1358LV]
Monday, Aug 31  10:15 AM – 11:00 AM PDT

VMware® vDefend™ Distributed Firewall and VMware® vDefend™ Distributed Intrusion Detection and Prevention System (IDS/IPS) provide security services in the kernel through processing of rules and signatures intrinsically within the virtual networking infrastructure. We will show the inner workings of the distributed services from an architectural standpoint and, more importantly, the best implementation techniques, as well as troubleshooting tools for examining the effectiveness of the strategy deployed. We will show the use of AI to simplify the configuration of the centrally managed protection mechanisms and greatly reduce the time and effort needed to put a tight security policy in place.

Chris McCain, Field CTO, Broadcom
Tim (vGandalf) Burkard, Principal Technical Learning Engineer, Broadcom

Self-Service Security for VMware Cloud Foundation Automation with VMware vDefend Distributed Firewall [SECB1119LV]
Tuesday, Sep 1  9:00 AM – 9:45 AM PDT

The core of delivering a VMware Cloud Foundation (VCF) private cloud experience to enterprise customers and cloud service providers is empowering their project and tenant admins with delegated, self-service security controls. This session will explore how VMware® vDefend™ Distributed Firewall delivers these self-service capabilities directly to customers consuming the VCF private cloud via VCF Automation. We will specifically discuss delegating vDefend Distributed Firewall controls and how enterprise admins, providers, and tenant admins can leverage it to ensure the highest levels of security.

Geoff Wilmington, Technology Product Management, Broadcom

Prescriptive Ransomware Defense for VMware Cloud Foundation Workloads with VMware vDefend Advanced Threat Prevention [SECB1466LV]
Tuesday, Sep 1   3:15 PM – 4:00 PM PDT

Ransomware is pervasive; your defense must be proactive. For VMware Cloud Foundation® (VCF) users, the optional phase of security is over. Join us to discover how to leverage VMware® vDefend™ Advanced Threat Prevention, including IDS/IPS, NTA, and NDR to stay ahead of threat actors. Whether you are just getting started or looking to optimize your existing stack, you will learn about a new prescriptive, built-in guided workflow with assessments and tailored security policies that will significantly improve your security posture.

Bopaiah Puliyanda, Senior Manager, Product Management, Broadcom

Security Reference Design for VMware Cloud Foundation [SECB1630LV]
Wednesday, Sep 2  11:30 AM – 12:15 PM PDT

In the era of decentralized data and AI-driven threats, security can no longer be a bolt-on feature—it must be the foundation. As organizations consolidate on VMware Cloud Foundation® (VCF), the challenge shifts from managing disparate security tools to implementing a unified, Zero Trust architecture that protects workloads from the silicon up to the cloud. Join us as we break down the blueprint for a hardened VCF and learn how to design security for VCF management and workload domains. We will move beyond basic configuration to explore a holistic architectural approach that integrates VMware® vDefend™ lateral security solutions. We will walk through the framework for building a resilient VCF private cloud: infrastructure protection, application ring fencing and microsegmentation, threat visibility, and ransomware prevention.

Pooja Patel, Director, Broadcom

Secure the Front Door: Hardened VMware vSphere Kubernetes Service with VMware Avi
and VMware vDefend [SECB1462LV]

Wednesday, Sep 2  12:45 PM – 1:30 PM PDT

Kubernetes (K8s) introduces a dramatically more agile model for modern applications. VMware® Avi™ and VMware® vDefend™ deliver critical security and load balancing for K8s workloads. VMware Avi and Avi Kubernetes Operator (AKO) redefine Kubernetes ingress by eliminating manual networking “plumbing.” Within VMware vSphere® Kubernetes Service (VMware VKS), installation is plug-and-play: AKO automatically provisions enterprise load balancing the moment your cluster is live. We are future-proofing this stack via the K8s Gateway API—the industry standard for modern AI Gateways. This role-oriented model simplifies life for developers and admins, providing the “front door” required for next-gen apps. Security remains a core pillar through Istio integration, where VMware Avi delivers high-performance mTLS, WAF, and deep observability. The session also highlights a top U.S. financial institution’s design and architecture for AKO. This unified approach ensures your VMware VKS environment is secure, modern, and simple to operate at scale.

Chris Grice, Technical Product Manager, Broadcom
Madhu Krishnarao, Sr. Product Manager, Broadcom

The Patching Dilemma: Do You Need Help with the Deluge of Vulnerabilities? [SECB1279LV]
Wednesday, Sep 2  2:00 PM – 2:45 PM PDT

The gap between vulnerability discovery and exploitation is shrinking at an unprecedented rate. As AI-driven tools automate the identification of zero-day flaws, traditional patch-all strategies have become mathematically impossible for modern enterprises. How do we keep up when the deluge never ends? This session explores a shift from reactive patching to risk-based orchestration. We will dive into the critical role of compensating controls, specifically focusing on how Virtual Patching via IDPS (Intrusion Detection and Prevention Systems) and Avi Web Application Firewall (WAF) provides the breathing room teams desperately need. Attendees will learn how to buy back time for testing and deployment without leaving their environment exposed to the next major exploit.

Geoff Shukin, Senior Product Manager, Broadcom
Stijn Vanveerdeghem, Senior Manager, Technology Product Management, Broadcom

Secure by Design: Eliminating Ransomware Blind Spots with VMware vDefend [SECB1311LV]
Wednesday, Sep 2  3:15 PM – 4:00 PM PDT

In a landscape where lateral movement defines modern attacks, infrastructure can no longer be a passive bystander. This session explores a security-first approach that embeds defense directly into the hypervisor to neutralize threats at the source. We provide a deep dive into the unique architectural advantage of VMware® vDefend™ and VMware Cloud Foundation® (VCF), demonstrating a methodology to “buy down” risk across your entire environment. Through technical insights and an end-to-end demo, you will discover how to achieve immediate “quick wins” such as virtual patching and distributed threat prevention to stop attackers before they gain a foothold.

Stijn Vanveerdeghem, Senior Manager, Technology Product Management, Broadcom

 

Theater presentation at VMware Explore 2025

Quick Talk

The Top 10 Agentic AI Security Risks and Threats Every IT Admin Should Know [CMTYQT1710LV]
Monday Aug 31 11:00 AM – 11:20 AM PDT

Learn about the top 10 security risks and vulnerabilities facing agentic AI applications, large language (LLMs), and MCP servers. In this session, we will provide an introductory overview of agentic AI components, real-world examples of AI security threats, and how you can prepare to mitigate those risks with VMware software solutions.

Catherine Fan, Technology Product Manager, Broadcom
Aziz Mohammed, Technical Product Manager, Broadcom

Tutorials

A Step-by-Step Tutorial for Stopping Brickstorm-Like Attacks Using VMware vDefend [SECT1642LV]
Monday, Aug 31  11:30 AM – 1:00 PM PDT

This session provides step-by-step guidance about how VMware® vDefend™ provides a robust architectural shield against such catastrophic events. We will dive into the deployment mechanics of VMware® vDefend™ Distributed Firewall and Distributed Intrusion Detection/Prevention (IDS/IPS) to demonstrate how micro-segmentation can effectively stop attacks in their infancy.

Andrew Hrycaj, Technical Product Manager, Broadcom
Geoff Shukin, Senior Product Manager, Broadcom

Meet the Expert Roundtables

Blocking and Tackling Ransomware with VMware vDefend: Practical Tips and Insights [SECM1756LV]
Tuesday, Sep 1  10:00 AM – 10:30 AM PDT

In this interactive whiteboard session, we move past the high-level marketing slides to focus on the technical “blocking and tackling” required to secure your private cloud using VMware® vDefend™. Among other topics, participants will gain technical insights into virtual patching, using Distributed IDS/IPS to shield vulnerable workloads from known exploits without the immediate need for disruptive guest-level patching, leveraging network detection and response (NDR) and sandboxing to identify behavioral signals of ransomware actors, and a lot more. Bring your questions and leave with a practical blueprint for making your infrastructure immune from ransomware.

Bopaiah Puliyanda, Senior Manager, Product Management, Broadcom

Code-Driven Security: Automating VMware vDefend Policy with Infrastructure as Code [SECM1509LV]
Tuesday, Sep 1  2:00 PM – 2:30 PM PDT

Stop managing security policies manually. This session moves beyond basic configuration to focus on operationalizing automation within your private cloud defense using infrastructure as code (IaC). We will demonstrate how to leverage code to automatically generate, deploy, and manage your VMware® vDefend™ Policy, making security policy a function of code that protects your environment from the ground up. We will dive deep into practical methods for codifying network segmentation using vDefend with virtual private clouds (VPCs), defining granular role-based access, and standardizing critical defenses like Layer 4/7 Firewall and Gateway Firewall configurations. By operationalizing this IaC approach, you will ensure consistent, scalable, and secure resource provisioning across all your projects, leading to streamlined and reliable deployment strategies.

Andrew Hrycaj, Technical Product Manager, Broadcom

Innovation Track

Governance of Micro-Segmentation Policies [INVB1744LV]
Wednesday, Sep 2  3:15 PM – 4:00 PM PDT

This session explores the critical pillars of microsegmentation governance, moving beyond the initial visibility phase into sustainable, long-term policy management. We will dissect the lifecycle of a policy—from discovery and authoring to automated enforcement and continuous auditing.

Kausum Kumar, Senior Manager, Technical Product Management, Broadcom

 

Registration is now open! Check out the content catalog and scheduling tool, using the vDefendAvi, and overall ANS Targeted Agendas to build your personalized VMware Explore schedule. Looking forward to seeing you in Las Vegas!