
Broadcom forces VMware clients to roll back crucial updates
In early May 2025, VMware's parent company Broadcom began issuing cease-and-desist letters to customers with perpetual licences whose customer support had expired. These letters, according to reports verified by Ars Technica and highlighted by Comparitech in an analysis, demand that customers remove all updates made after the end of their support contracts, under threat of audits and possible litigation.
The only exception to this demand allows customers to retain updates addressing zero-day vulnerabilities, or those with a Common Vulnerability Scoring System (CVSS) score of 9.0 or higher. All other security updates must be rolled back in compliance with Broadcom's current policy.
Network administrators and IT professionals have expressed alarm at this directive's potential security and operational ramifications. According to users active on technical forums, including Reddit's /r/sysadmin, affected companies are placed in a difficult position: either remove important updates and risk security lapses, switch to more expensive subscription packages, or face the possibility of legal actions.
Comparitech's analysis described this as leaving companies in a "zero-sum game" that could jeopardise future business prospects and the security of sensitive data.
"Broadcom has effectively created a zero-sum game in which many existing customers who were grandfathered in after it purchased VMWare must now make a choice that could cost them millions and risk not only the future of their company but also the secure data that they maintain," the analysis stated.
The policy has broader cybersecurity implications because rolling back updates reintroduces known vulnerabilities into network environments. These are security flaws that cybercriminals, including ransomware groups such as those behind the notorious WannaCry attacks, have previously exploited.
"Update and security patch rollbacks are not benign. They reintroduce well-documented security flaws that cyber criminals have already learned to scan for and exploit," the analysis explained.
The security concern is that ransomware gangs may target these known vulnerabilities, exploiting them to breach companies that had already patched the flaws.
"Broadcom's efforts to force security rollbacks effectively threaten license holders with an order-of-magnitude increase in their risk of a data breach. While the company holding the license ultimately has the legal responsibility and business imperative to protect data, such actions on Broadcom's part raise serious ethical questions when businesses are forced to decrease protections and increase risk," Comparitech notes.
Beyond security, update rollbacks could negatively affect the stability of critical IT infrastructure. Many updates patch security holes and deliver performance improvements and compatibility enhancements. Reverting to previous software states may destabilise hypervisors, break integrations with backup or disaster recovery tools, and disrupt operations in environments where reliability is crucial.
"When companies are forced to revert their systems to an earlier state, it can quickly destabilise hypervisors, completely invalidate integrations with backup or DR tooling, and painfully disrupt resource scheduling for virtual workloads," Comparitech warned.
For organisations in sectors such as education, healthcare, and government, where large volumes of regulated personal or health information are managed, system failures and downtime can become significant operational and financial risks.
The sentiment among long-time VMware customers is described as betrayal and frustration.
"This is like a mafioso shaking down a shopkeeper for protection money. I swear, if they won't be reasonable on my next phone call with them, then I will make it my mission — with God as my witness — to break the land speed record for fastest total datacenter migration to Hyper-V or Proxmox or whatever and shutting off ESXi forever. I'm THAT pissed off," one IT professional commented in April 2025 on /r/sysadmin.
Comparitech's analysis suggests that Broadcom's actions put companies in a position where expensive migration to alternative platforms or subscription services may be the only safe option. However, these can be lengthy and complex processes. Many organisations may face significant costs or risks during the transition, and some may be unprepared to switch off VMware infrastructure quickly.
With Broadcom reportedly willing to take legal action against non-compliant customers, as seen in an ongoing case against Siemens, the only immediate recourse for affected companies is to fortify their IT security. Steps recommended include hardening network perimeters, isolating vulnerable systems, implementing strict access controls, enhancing monitoring and detection, regular vulnerability scanning, auditing backup systems, reducing internet-facing exposures, and establishing a rapid response plan during the migration period.
Broadcom completed its acquisition of VMware in 2023 and subsequently shifted VMware's licensing strategy. Perpetual licences for VMware products were discontinued, and new requirements pushed customers towards pricier, multi-year subscription models. In early 2024, the company also ended the availability of VMware's free ESXi hypervisor. It began restricting access to software downloads and binaries for customers without an active support-and-subscription agreement.
"Broadcom's push to change VMware's licensing strategy was terrible from a customer service and customer satisfaction standpoint, but not immediately dangerous to customers and their data. However, the company's new efforts to strong-arm perpetual license holders into pricier subscription packages by canceling or failing to allow renewals of SnS agreements push its strategy into potentially unethical realms that endanger companies and their customers," Comparitech noted in its analysis.
Comparitech plans to continue monitoring ransomware attack trends to assess whether future incidents can be traced to systems exposed through the forced rollback of security updates under Broadcom's policy.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Techday NZ
2 days ago
- Techday NZ
NetApp brings FSx for ONTAP to Amazon EVS for enhanced cloud migration
NetApp has confirmed that Amazon FSx for NetApp ONTAP is now available as an external storage option for Amazon Elastic VMware Service (Amazon EVS) on Amazon Web Services (AWS). Amazon EVS is a recently introduced AWS service that enables customers to operate VMware Cloud Foundation (VCF) within their Amazon Virtual Private Cloud (Amazon VPC), running alongside other applications. This service aims to aid organisations in moving VMware workloads to AWS, extending their VMware environments and providing added business agility. Cloud migration support The integration leverages NetApp's data management and protection functions within the cloud environment provided by AWS. It is designed to help customers transition their VMware workloads to AWS without requiring changes to application platforms, refactoring, or adjustments to existing workflows. This new option is intended to address the complexities associated with cloud migration for mission critical workloads. By doing so, businesses can eliminate outdated infrastructure, lower operational expenses, and maintain important business timelines. NetApp noted that an effective data strategy is necessary to avoid challenges such as unplanned costs, IT sprawl, and disconnected services. NetApp is currently the only enterprise storage provider with a first-party data storage service built into AWS. Users who have adopted Amazon FSx for NetApp ONTAP have achieved cost reductions of up to 50 percent. The service's built-in data management capabilities also support improved planning and reduced total cost of ownership for VMware environment migrations. Customer and partner perspectives "Customers utilizing Amazon EVS with FSx for ONTAP can now enjoy the same data efficiency, protection, and automation they trust on-premises," said Pravjit Tiwana, Senior Vice President and General Manager, Cloud Storage at NetApp. "Through our collaboration with AWS, we're making it easier to move critical workloads to the cloud and manage them at scale." Matthew Swinbourne, CTO Cloud Architecture at NetApp Asia Pacific, also commented on the regional impact: "We foresee incredible benefits for Asia Pacific enterprises with the launch of Amazon EVS. The native integration of Amazon FSx for NetApp ONTAP into Amazon EVS elevates the security, efficiency and performance of VMware workloads whilst reducing the TCO for our customers. With this launch, APAC organizations can achieve the flexibility, performance, and cost benefits that they need to accelerate their cloud ambitions." Xtravirt, a NetApp Preferred Partner and AWS partner, expressed support for the integration. Robin Gardner, CCO at Xtravirt, stated: "Enabling support for FSx for ONTAP on Amazon EVS gives customers more granular control over the data powering some of their most important workloads. Customers will be able access NetApp's advanced data management functionality to reduce the overhead of managing virtual environments and more efficiently and securely manage hybrid deployments." New features and functions NetApp now provides customers with several enhancements intended to simplify the management of advanced workloads in the cloud. These include the general availability of Amazon FSx for NetApp ONTAP as a storage option for Amazon EVS, improved migration processes using BlueXP workload factory, and expanded disaster recovery options within BlueXP for VMware. The disaster recovery solution is compatible with both NFS- and VMFS-based datastores, supporting file and block protocols. The company has also introduced further measures to enhance ransomware protection for Amazon EVS workloads. Notably, the NetApp ONTAP autonomous ransomware protection for FSx for ONTAP can detect and respond to ransomware events in real time. This is complemented by the BlueXP ransomware protection service, which supports end-to-end orchestration for customers to safeguard their data in AWS environments and reduce downtime by identifying threats at the storage layer. NetApp emphasised that, while its technologies add an important layer of ransomware defence, no detection or prevention system can provide absolute protection. There remains the possibility that some ransomware attacks might go undetected. Follow us on: Share on:


Techday NZ
2 days ago
- Techday NZ
NetApp & AWS extend FSx for ONTAP support to Amazon EVS
NetApp and Amazon Web Services have announced that Amazon FSx for NetApp ONTAP is now a supported external storage option for the Amazon Elastic VMware Service (Amazon EVS). The development means customers can run VMware Cloud Foundation (VCF) directly within their Amazon Virtual Private Cloud (Amazon VPC), supporting the migration and management of critical VMware workloads to the cloud, while maintaining their existing data management workflows. With the inclusion of Amazon FSx for NetApp ONTAP as a storage option for Amazon EVS, organisations are able to leverage NetApp's data management and protection in the AWS environment. This is set to simplify and accelerate the migration of workloads to AWS, without requiring applications to be re-platformed or re-factored. Migration and efficiency Migrating business-critical workloads to the cloud is frequently seen as a way to remove legacy infrastructure, lower operational costs, and fulfil business timelines. However, doing so requires effective data strategies to manage risks related to costs, IT complexity, and fragmented services. NetApp is currently the only enterprise storage solution provider with a first-party storage service natively built on AWS, which allows customers to accelerate workloads in the cloud by using technologies designed specifically for the AWS ecosystem. According to NetApp, customers have reported reductions in costs of up to 50 percent after adopting Amazon FSx for NetApp ONTAP. By integrating FSx for ONTAP with their VMware environments, organisations can take advantage of Intelligent Data Infrastructure to improve migration planning and lower total cost of ownership through built-in management capabilities. "Customers utilizing Amazon EVS with FSx for ONTAP can now enjoy the same data efficiency, protection, and automation they trust on-premises," said Pravjit Tiwana, Senior Vice President and General Manager, Cloud Storage at NetApp. "Through our collaboration with AWS, we're making it easier to move critical workloads to the cloud and manage them at scale." New capabilities NetApp has released several new features to further support customers managing advanced workloads in the cloud. Amazon FSx for NetApp ONTAP now supports Amazon EVS, which is designed to simplify deployments and provide a ready-to-use VCF environment on AWS. VMware administrators migrating to AWS can use the same VCF tools present in their on-premises setups. FSx for ONTAP as an external storage solution in the Amazon EVS environment brings data management and protection features intended to reduce overhead, lower costs, and bolster cyber resilience. Additionally, the migration advisor feature within BlueXP workload factory for AWS now supports Amazon EVS workloads. This tool automates the discovery of on-premises virtual machines, provisioning of FSx for ONTAP, and placement of datastores in Amazon EVS, aiming to simplify and speed up migration processes. BlueXP disaster recovery for VMware has been expanded to integrate with Amazon EVS, utilising FSx for ONTAP as a disaster recovery target. Supported datastore configurations include both file-based (NFS) and block-based (VMFS using iSCSI) protocols. This aims to provide customers with flexible and efficient disaster recovery solutions. Ransomware protection NetApp has also enhanced ransomware protection for workloads running on Amazon EVS. The ONTAP autonomous ransomware protection (ARP) for FSx for ONTAP monitors and responds to ransomware events in real time, while BlueXP ransomware protection service extends orchestration capabilities for customers seeking to improve their defence against such threats. According to NetApp, enabling these features in AWS aims to protect customer data and limit downtime through proactive detection at the storage layer across hybrid cloud environments. Partner support Xtravirt, a NetApp Preferred Partner and AWS partner, expressed support for the announcement, stating that it will benefit businesses seeking to move VMware workloads to the public cloud. "Enabling support for FSx for ONTAP on Amazon EVS gives customers more granular control over the data powering some of their most important workloads," said Robin Gardner, CCO at Xtravirt. "Customers will be able access NetApp's advanced data management functionality to reduce the overhead of managing virtual environments and more efficiently and securely manage hybrid deployments." NetApp maintains that while no ransomware detection or prevention system can guarantee complete safety, its technology serves as an important additional layer of defence for customers deploying critical workloads on AWS.


Techday NZ
3 days ago
- Techday NZ
NetApp brings enhanced data management to Amazon EVS on AWS
NetApp has announced that Amazon FSx for NetApp ONTAP will now be available as a supported external storage option for Amazon Elastic VMware Service (Amazon EVS) on Amazon Web Services (AWS). Amazon EVS is a newly available service that enables customers to run VMware Cloud Foundation (VCF) within their Amazon Virtual Private Cloud (Amazon VPC), alongside other cloud workloads. This offering allows businesses to migrate VMware environments to AWS without the need to re-platform or re-factor their existing applications, extending their on-premises setups and unlocking additional flexibility for transformation initiatives. The integration is designed to combine NetApp's data management and protection tools with AWS's platform capabilities, aimed at helping customers simplify and speed up workloads migrations to the AWS Cloud. The move also allows organisations to avoid disruption to their data management workflows while leveraging AWS scalability and resilience. Migrating key workloads to the cloud is considered a pathway for businesses to drive change by moving away from ageing infrastructure, lowering operational expenditures, and meeting vital timelines for their operations. The transition to cloud workloads, however, requires a robust data management strategy to avoid potential challenges, such as unforeseen costs, fragmented services, and an overly complex IT landscape. NetApp has positioned Amazon FSx for NetApp ONTAP as a solution for enterprises seeking native cloud data storage, claiming it as the only enterprise storage offering built natively on AWS. By adopting the joint solution, some customers have reported operational cost reductions of up to 50 percent. The integration also aims to help improve migration planning and lower the total cost of ownership through integrated data management features. "Customers utilizing Amazon EVS with FSx for ONTAP can now enjoy the same data efficiency, protection, and automation they trust on-premises," said Pravjit Tiwana, Senior Vice President and General Manager, Cloud Storage at NetApp. "Through our collaboration with AWS, we're making it easier to move critical workloads to the cloud and manage them at scale." Matthew Swinbourne, CTO Cloud Architecture at NetApp Asia Pacific, commented on the expansion of services in the region. "We foresee incredible benefits for Asia Pacific enterprises with the launch of Amazon EVS. The native integration of Amazon FSx for NetApp ONTAP into Amazon EVS elevates the security, efficiency and performance of VMware workloads whilst reducing the TCO for our customers," Swinbourne said. "With this launch, APAC organizations can achieve the flexibility, performance, and cost benefits that they need to accelerate their cloud ambitions." Expanded features NetApp has outlined several new features in support of the integration. These include: Support for using Amazon FSx for NetApp ONTAP as external storage for Amazon EVS, allowing VMware administrators to migrate virtual machines to AWS using familiar tools and providing data management functionality to decrease total ownership costs and boost cyber resilience. The migration advisor feature within BlueXP workload factory for AWS, which is now compatible with Amazon EVS workloads for automated virtual machine discovery, storage provisioning, and data store placement. Enhanced disaster recovery for VMware within BlueXP, supporting integration with Amazon EVS and using FSx for ONTAP as a disaster recovery target. This supports both NFS and VMFS datastore formats, ensuring comprehensive recovery scenarios. Additional ransomware protection, including NetApp ONTAP autonomous ransomware protection for FSx for ONTAP and orchestration capabilities in BlueXP ransomware protection service. These features aim to detect ransomware threats in real time and help minimise downtime. Xtravirt, an AWS and NetApp Preferred Partner, welcomed the announcement. Robin Gardner, CCO at Xtravirt, said, "Enabling support for FSx for ONTAP on Amazon EVS gives customers more granular control over the data powering some of their most important workloads. Customers will be able access NetApp's advanced data management functionality to reduce the overhead of managing virtual environments and more efficiently and securely manage hybrid deployments." NetApp also noted that, while it offers autonomous ransomware protection, no ransomware prevention system can provide complete protection, and attacks may still go undetected. However, the company believes its technology forms a useful additional layer of defence for customers overseeing hybrid and public cloud environments. Follow us on: Share on: