At VMware Explore, Broadcom introduced comprehensive security, identity, and open-source supply-chain solutions designed for enterprise AI deployments. As organizations move from static model querying to autonomous agentic architectures, workloads increasingly use emerging communication protocols such as the Model Context Protocol (MCP) and agent-to-agent (A2A) networking. These distributed frameworks create new attack surfaces across autonomous agents, tools, enterprise data stores, and large language models (LLMs).
To address these vulnerabilities, Broadcom is deploying an integrated defense architecture across three core products: Broadcom AgentMinder, VMware vDefend, and VMware Avi Load Balancer. Additionally, the company announced TrueSource by Broadcom, a commercial program providing cryptographically verified, human-validated open-source runtimes and data services to mitigate software supply-chain risks.
Agentic Zero Trust and Lateral Defense via VMware vDefend
Within VMware Cloud Foundation (VCF), VMware vDefend extends hypervisor-level Zero Trust microsegmentation to agentic AI traffic. As autonomous workflows connect disparate infrastructure tiers, vDefend implements continuous network traffic inspection to automatically discover and map active agentic components, including MCP servers, backend LLM endpoints, operational tools, and connected datastores.
This continuous visibility enables the automated detection of shadow AI deployments and unauthorized inference calls across the private cloud fabric. To defend against the rapid weaponization of software vulnerabilities, vDefend incorporates an agentic AI pipeline that generates Intrusion Detection and Prevention System (IDPS) signatures automatically at machine speed. These signatures drive distributed virtual patching across the cluster, shielding workloads and host environments without requiring immediate application refactoring or operational downtime.
Application-Layer Protection with VMware Avi Load Balancer
Operating as an ingress and traffic management plane integrated with Kubernetes and VMware vSphere Kubernetes Service (VKS), VMware Avi Load Balancer delivers AI-aware web application firewall (WAF) and API protection (WAAP). Scaled for multi-terabit throughput in elastic environments, Avi inspects payload contents to prevent misuse of agents and tools.
The platform monitors transactions between agents and MCP tools, blocking malicious execution vectors such as remote code execution (RCE), command injection, and malicious file uploads. By profiling baseline communication patterns between agents, models, and tools, Avi identifies zero-day anomalies and isolates rogue sessions in real time. Additionally, the load balancer applies data loss prevention guardrails to outbound traffic streams, preventing the unauthorized exfiltration of sensitive API tokens, cryptographic credentials, personally identifiable information (PII), and internal financial records.
Autonomous Agent Governance Through Broadcom AgentMinder
Broadcom unveiled AgentMinder, a dedicated control plane designed to govern autonomous AI agents as they transition from text generation to active business process execution. AgentMinder treats each deployed agent as an enterprise-grade identity, binding its execution scope to a declared mission, explicitly permitted intents, vetted tools, and authorized resource boundaries.
Policy enforcement occurs via a cloud-native runtime gateway that evaluates the execution context, verifying agent identity, tool authorization, declared intent, and targeted data sources before each invocation. To meet enterprise compliance and security standards, AgentMinder integrates with OpenTelemetry. This framework records machine-readable audit logs for every agent interaction, establishing a verifiable chain of custody, surfacing operational telemetry, and enabling automated anomaly detection across complex, multi-agent workflows.
TrueSource Secures the Open-Source Software Supply Chain
Alongside infrastructure security, Broadcom launched TrueSource by Broadcom to address systemic risks in the enterprise open-source supply chain. With generative AI accelerating vulnerability discovery and exploitation, Broadcom emphasized that unverified automated patching introduces operational instability. Recent data from 1Password’s Off-by-1 Labs indicated that only 26 percent of 6,000 evaluated AI-generated patches successfully resolved vulnerabilities without breaking application functionality.
TrueSource establishes a curation model based on clean-room builds, upstream maintainer collaboration, automated repository scanning, and human code review:
Spring Enterprise provides commercial support and hardened releases from the core maintainers of the Spring framework. Broadcom engineers leverage frontier AI models to scan the framework and its broader dependency tree, consuming over 12 billion model tokens in scanning operations over recent months, while maintaining mandatory human engineering sign-off on every fix. Security patches are delivered simultaneously across both open-source and active enterprise release lines prior to public CVE disclosure. Coverage encompasses the complete dependency tree of more than 5,000 verified Java libraries, including Apache Tomcat and Kotlin, pinned and signed to specific Spring Boot releases. Point patches that contain only the remediation allow security teams to deploy critical CVE fixes without requiring larger framework upgrades.
TrueSource Trusted Artifacts delivers secure, clean-room SLSA Build Level 3 builds for libraries across Java, Python, and Node.js ecosystems. The curation adheres to strict reference architectures vetted by Broadcom software teams and is complemented by the Bitnami Secure Images catalog, which provides hardened container runtimes.
TrueSource Data Services extends this methodology to critical stateful infrastructure, providing validated builds, Helm charts, Kubernetes operators, and support for PostgreSQL, RabbitMQ, MySQL, and Valkey.
Licensing and Availability
Broadcom stated that Spring Enterprise, TrueSource Trusted Artifacts, and TrueSource Data Services are available immediately under tiered enterprise site-licensing models. These offerings provide automated pull-request remediation tooling, blast-radius impact analysis dashboards, and early-access remediation pipelines for zero-day vulnerabilities discovered in production environments.




Amazon