Defending Modern Enterprise Software Against AI-Powered Threats with VMware Tanzu Spring @VMwareTanzu
Defending Modern Enterprise Software Against AI-Powered Threats with VMware Tanzu Spring  @VMwareTanzu
Uploaded June 2026 | Updated September 2026, 2 hours ago
Enterprise Java security has changed significantly in the last two months. A massive 1,766% increase in Spring security reports, combined with AI-powered cyberattacks, has made traditional “wait-and-patch” methods obsolete. With threats emerging in hours, reactive strategies are no longer safe.

This executive roundtable discussion with the Spring engineering leadership team explores moving to a proactive, first-party defense. We will analyze how clean-room builds and new operational strategies that can help organizations stay resilient in this accelerated threat environment. Join us to learn how to secure your applications with Tanzu Spring.

Learn more about VMware Tanzu Spring: enterprise.spring.io

Panelists:

@michaelminella - Director, Open Source Spring at VMware Tanzu (Broadcom). Runs the team that commits to the Spring open source frameworks.

Ryan Morgan - VP, R&D for the App Developer and Operator group at VMware Tanzu. Has been overseeing the Spring framework for 15+ years.

@ciberkleid - Developer Advocate, VMware Tanzu. Works across the Tanzu portfolio including Spring and the platform.

@thecote - VMware Tanzu.

A few moments worth catching:

Spring shipped 17 CVEs in all of last year. Last week alone: 70+. (Michael Minella)

Security reports went from ~7/month historically to 55 in March, then 112 community + 370 from internal scanning in April.

"I can take a library of security reports, pump it through these top-end models and say, is there a path from point A to point B without that one super-critical vulnerability? And it'll say, yeah, I can go from here to here to here. The skill level required to accomplish that has dropped dramatically." (Michael Minella, on AI-chained "narrative" attacks)

"That idea of 'if it's not broken, don't fix it' is dissolving. It probably is broken, and you need to fix it." (Cora Iberkleid)

1,800 dependencies that Spring manages, now clean-room rebuilt with SLSA level 3 provenance using the Bitnami architecture.

Open source release train compressed from two weeks to five days; enterprise patches now land all at once.

"Customers ask if we're going to release more often. My question back is: if I did, could you consume it any faster? And the answer is almost always no." (Michael Minella, on the downstream bottleneck)

The fix / fork / ditch three-bucket triage pattern for handling the deluge of vulnerable open source dependencies.

The Tanzu 1-2-3: Tanzu Spring Essentials (CVE coverage backported into the 2030s), App Assessment, and Tanzu Platform for continuous patching with zero-downtime upgrades.

Index:

00:00 Welcome and panel introductions
03:30 What AI-found vulnerabilities actually look like: cache pollution, zip bombs, untrusted input
03:41 Chained "narrative" attacks - and why the skill floor just collapsed
06:36 The spike: 7 reports/month to 55 to 112 community + 370 internal
07:49 Compressing the release train (2 weeks to 5 days), enterprise patches landing all at once
10:11 Being the CNA: source of record, right of first refusal, validating fixes before disclosure
14:15 The fix / fork / ditch triage for open source dependencies
18:32 "If it ain't broke, don't fix it" is dissolving (Cora)
20:48 Clean-room rebuilding all 1,800 Spring-managed dependencies at SLSA level 3
23:50 Gear shift, not a spike - the new baseline (30-50/month)
25:00 17 CVEs all of last year vs. 70+ last week alone
25:10 OpenRewrite recipes + App Advisor for automated, deterministic upgrades
30:15 "If I released more often, could you consume it any faster?"
35:19 Securing the full stack: VM, container, JDK, OS - automated reboot and patch
40:58 The Tanzu 1-2-3: Spring Essentials, App Assessment, Tanzu Platform
43:55 Close

#SpringSecurity #VMwareTanzu #EnterpriseJava #AIThreats #SoftwareSupplyChain #SpringBoot #CVE
Defending Modern Enterprise Software Against AI-Powered Threats with VMware Tanzu SpringTanzu GM Purnima Padmanabhan, Accelerating AI App DeliveryBeyond REST - Crafting a Modern GraphQL API LiveVMWare Tanzu Greenplum - Parque Schema Evolution Support in PXF 8.0.1DevX metrics at Home Depot.Don’t forget what I told you yesterday - AI memory and the mind palaceOf Microservices and Monoliths, and Everything in BetweenToo polite to be useful - when AI safety prompts kill the vibeThe Risk of Relying on AI for Platform EngineeringIt turns out survival was mandatory. Or, the muggle enterprises adapted better than expected. ⏬We Restructured Our Whole Org for AI - Heres HowApplication Operator Experience with Tanzu Platform
VMware Tanzu |

Defending Modern Enterprise Software Against AI-Powered Threats with VMware Tanzu Spring

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER