Watch on YouTube
Watch on Vimeo
Frontier AI has compressed threat timelines, allowing attackers to weaponize vulnerabilities in hours rather than months. For enterprise infrastructure, running production AI requires a fundamental engineering pivot: prioritizing continuous platform hardening over rapid feature delivery. In this session, we break down how VCF adapted its architecture to counter AI-driven threats. We walk through our security delivery model, combining monthly express updates with predictable quarterly releases to maintain zero-day resiliency without operational friction. We showcase how Broadcom uses Frontier AI internally to simulate multi-vector attacks against VCF before adversaries do. Finally, we demonstrate VCF’s hypervisor-level virtual patching, showing how inline network microsegmentation instantly insulates sensitive AI workloads from exploit vectors without disruptive downtime. Bob Plankers opened by describing how much the threat landscape has shifted since late 2025, when AI became capable enough to act as a force multiplier for attackers and defenders alike. He explained that AI excels at analyzing source code, which has driven a flood of CVEs against open-source projects like the Linux kernel and created supply chain pressure for vendors such as Broadcom. AI can also find configuration weaknesses, chain together low- and moderate-severity vulnerabilities that organizations never bothered to patch, produce flawless multilingual phishing, clone voices for social engineering, and generate custom malware for each victim, as seen with Brickstorm. He noted that AI-driven attacks can move very slowly to stay under detection thresholds, and that anyone with a modest GPU can run an uncensored open model to build a hacking bot.
Plankers urged customers to practice “security always” rather than claiming “security first,” to actually implement zero trust, and to avoid the survivorship bias of assuming no breach means their defenses work. He stressed that traditional controls such as patching, logging, identity management, isolation, and recovery remain effective, and that every VCF and vSphere feature maps to confidentiality, integrity, or availability. He highlighted snapshots as a recovery tool that has improved dramatically, with vSAN ESA using B-trees instead of delta files, consolidation no longer stunning VMs, and compression and deduplication keeping costs low. In his lab, the protection and recovery appliance stored more than a thousand snapshots of twelve VMs in about 25 GB, letting him patch weekly and revert quickly when something broke. He then covered live patching, which uses partial maintenance mode and a fast suspend-and-resume to swap the virtual machine monitor in microseconds without rebooting or evacuating hosts, while cautioning that large updates like 9.1.0 to 9.1.1 still require traditional vMotion and that change advisory boards remain a hurdle. VCF 9.1 also introduced a deprivileged user-level virtual machine monitor, so an attacker who escapes a VM lands with no permissions rather than as root.
On the organizational side, Plankers said Broadcom joined Anthropic’s Project Glasswing and its Mythos preview in April 2026, and that AI is now part of its secure development lifecycle, with different models and effort levels surfacing different findings. The VCF roadmap has been reoriented around security, with monthly express patches, quarterly releases like 9.1.1 that ship security features early rather than waiting for 9.2, and a commitment to avoid further major architectural changes in the 9.x series so customers can upgrade to 9.1. Broadcom signs its code, runs AI and conventional code reviews and scanners, pursues FIPS 140-3 and Common Criteria validation, and publishes a CVE disposition CSV and SPDX-format SBOM with each build so customers can reconcile scanner findings, though it keeps release notes vague to avoid educating attackers. In response to delegate questions, he said 9.1 hardens the management plane through process isolation and removing unneeded components, that VM escape vulnerabilities typically appear about once per major version and are less severe on 9.1, and that a predictable monthly patch date is a goal Broadcom is still working toward. He closed by comparing VCF to the star fort of Palmanova, Italy, built in response to the siege cannon, as a trusted place that can be defended when necessary.
Personnel:
Thank you for being part of the Tech Field Day community! Our mailing list is a great way to stay up to date on our events and technical content, and we appreciate your signup.
We promise that we’ll never spam you, send ads, or sell your information. This list will only be used to communicate with our community about our events and content. And we’ll limit it to no more than one message per week.
Although we only need your email address, it would be nice if you provided a little more information to help us get to know you better!