URL has been copied successfully!
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

The WAF gap no one is talking about

Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your APIs at machine speed, at machine scale, are the fastest-growing source of that traffic. When a developer spins up an MCP server, when an internal copilot starts calling your internal APIs, or when an autonomous agent begins iterating on a task, it generates a kind of traffic that legacy WAF rules simply don’t know how to interpret. The recent Hugging Face incident made this concrete. Attackers exploited exactly the kind of gap that traditional WAF rulesets leave open: API-layer and AI-adjacent attacks that don’t match classic signatures and fly under the radar of existing tools. That gap is now closed.

Introducing Salt Managed Rules for AWS WAF

Today, we’re announcing the availability of Salt Managed Rules for AWS WAF, available now in AWS Marketplace. This is the first AWS WAF Partner Managed Ruleset purpose-built to protect both APIs and the AI agents that drive them. Existing AWS WAF customers can subscribe directly from the AWS console and attach the ruleset to their web ACLs in minutes. No new agents to deploy. No architecture changes. No long procurement cycles.

What the ruleset actually does

Advanced API threat detection

The ruleset blocks common and complex API attack vectors that standard WAF rules miss: credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT-based anomalies. These are the real attack patterns targeting production APIs today.

Industry-first MCP awareness

This is a first in the industry. The ruleset identifies and labels traffic from MCP endpoints, blocks unauthenticated MCP access, and gives security teams deeper observability into MCP interactions inside their AWS WAF environments. As MCP adoption accelerates, this visibility is no longer optional.

Context-aware rate limiting

Not all rate limiting is equal. The ruleset applies smart limits to sensitive parameters like user IDs and email addresses, stopping enumeration and abuse patterns that standard rate rules miss entirely.

Security signal enrichment

The ruleset labels critical request attributes including auth headers, user identifiers, and GraphQL queries. That enrichment flows into your downstream analytics and detection systems, boosting fidelity and reducing noise across your entire security stack.

Why this matters now

“AI agents are transforming how applications are built, and APIs are the layer where those agents act,” said Roey Eliyahu, CEO and Co-founder of Salt Security. “By bringing Salt’s API and agentic security intelligence directly into AWS WAF as managed rules, we’re giving every AWS customer an easy button that deploys in minutes, so organizations can immediately see and stop the API and AI agent threats that legacy rules were never built to catch.” Salt has been building behavioral detection for APIs since 2016. That depth of expertise is what makes this ruleset different from anything else on the market. We didn’t bolt AI security onto an existing product. We built detection for how agents actually behave, and we packaged it so any AWS WAF customer can get that protection today.

Get started

Salt Managed Rules for AWS WAF is available now across all commercial AWS Regions and globally via Amazon CloudFront. Subscribe from the AWS Marketplace and attach the ruleset to your existing web ACLs directly from the AWS console. Learn more at the AWS Marketplace listing. Questions? Reach out to the Salt team at salt.security.

First seen on securityboulevard.com

Jump to article: securityboulevard.com/2026/08/salt-debuts-first-aws-waf-managed-ruleset-for-ai-agent-and-api-protection/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link