Skip to content
theCUBE

UPDATED 16:59 EDT / AUGUST 31 2026

Umesh Mahajan, vice president and general manager of the Application Networking and Security division at Broadcom, talks to theCUBE about securing cloud infrastructure and protecting agentic AI workloads at VMware Explore 2026 AI

Agentic AI blows up the attack surface as security moves into the infrastructure layer

The enterprise attack surface is expanding rapidly as agentic AI brings a constantly shifting cloud infrastructure into play.

That pace is pushing security decisions down toward the virtualization layer, where policy can be enforced without slowing traffic. Perimeter defenses alone no longer hold, and enterprises that delay a broader lateral security program risk falling behind increasingly automated attacks, according to Umesh Mahajan (pictured), vice president and general manager of the Application Networking and Security Division at Broadcom Inc.

“This is the time where you can’t put off security any longer,” Mahajan said. “‘Oh, I got a perimeter firewall. I’m good.’ No, no, no – not good. It can be bypassed. Now the security gurus or experts are saying, ‘No, you can’t take two years, three years. You have to deploy lateral security.'”

Mahajan spoke with theCUBE’s John Furrier at VMware Explore 2026, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed agentic AI’s effect on the enterprise attack surface, zero-trust enforcement and API protection for Kubernetes workloads. (* Disclosure below.)

Building zero trust into cloud infrastructure

Enterprises have often bought security tools piecemeal over the years, and the seams between them are where attackers operate. Broadcom’s answer is an integrated software stack in which the elements share context, delivered through its vDefend and Avi Load Balancer product lines, Mahajan explained.

“Our customers have bought multiple security products. They can’t put it together,” he said. “It’s like buying Swiss cheese. Yeah, you have pieces of security, but you have plenty of holes which people can drive through.”

Scale is the other constraint, Mahajan noted. AI workloads generate heavy east-west traffic and punish any inspection step that adds delay, which is why the company has pushed enforcement into the hypervisor rather than a separate appliance tier, part of a wider update to VMware’s security portfolio for AI-era threats. That includes firewalling and intrusion detection and prevention, with the company aiming to handle security processing at high throughput while keeping latency low.

“We are doing 75 terabits per vCenter cluster for firewalling. We are doing 17 terabits for IDS IPS, and the other aspect is also latency,” Mahajan said. “Because in AI workloads, latency matters, so our security is done at the hypervisor level.”

In other words, Broadcom is pushing security enforcement into the hypervisor to inspect traffic at scale without introducing the latency of sending it through separate security appliances. But protecting those workloads also requires visibility into what is running, Mahajan noted. Agents and Model Context Protocol services are transient, so administrators need a real-time picture of what is authorized and what is shadow IT before they can quarantine anything, and that visibility work is now landing alongside private cloud modernization programs. Bolting protection on later, once the cloud infrastructure is already carrying production AI traffic, is the failure mode executives are trying to avoid.

“It has to be at the infrastructure level; it has to be at scale,” he said. “Otherwise, when are you going to do it? Two years from now, by that time you’ll be compromised.”

Here’s the complete video interview, part of SiliconANGLE’s and theCUBE’s coverage of VMware Explore 2026:

(* Disclosure: TheCUBE is a paid media partner for the VMware Explore 2026 event. Neither Broadcom, the sponsor of theCUBE’s event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)

Photo: SiliconANGLE

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network

Are you an AWS customer?  Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/

 

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Send us a news tip

Send us a News Tip

  • This field is for validation purposes and should be left unchanged.
  • Max. file size: 244 MB.

Sign in

SIGN IN

Bio

Ethics statement

Extract the signal from the noise

Get SiliconANGLE updates and analysis.

Contact us

Partner with us

Contact us

Guest inquiry