CyberSecurity SEE

Salt Security Introduces First-Ever AWS WAF Managed Ruleset for AI Agents and API Protection

Salt Security Launches Groundbreaking AWS WAF Managed Ruleset for AI Agents and API Protection

In a significant development for cybersecurity, Salt Security has introduced what it claims is the industry’s first managed ruleset for AWS Web Application Firewall (WAF) tailored specifically to protect Application Programming Interfaces (APIs) and AI agents. This innovative solution aims to enhance existing AWS WAF capabilities, responding to the unique challenges posed by the increasing use of agentic AI in modern applications.

The newly unveiled Salt Managed Rules for AWS WAF were announced during the prestigious Black Hat USA 2026 conference. They are now available through the AWS Marketplace as part of the AWS WAF Partner Managed Rules program. This offering allows AWS customers to seamlessly deploy advanced protections for their APIs and AI agents directly from the AWS console, eliminating the need for additional infrastructure, proxies, or traffic redirection.

The launch comes at a time when more organizations are turning to APIs to drive their digital services. Concurrently, AI agents are becoming one of the fastest-growing sources of API traffic. According to Salt Security, traditional WAF rulesets often lack the contextual awareness necessary to effectively identify API-specific attacks and the behavioral patterns associated with autonomous AI agents, which can result in substantial security gaps.

To address these concerns, the new managed ruleset provides robust protection against various typical API attack techniques. These include credential brute force attacks, excessive GraphQL queries, server-side request forgery (SSRF), prototype pollution, and anomalies based on JSON Web Tokens (JWTs). This comprehensive coverage is essential for organizations that rely heavily on APIs and rapidly deploy AI solutions across their platforms.

A notable feature of the managed ruleset is its incorporation of support for the Model Context Protocol (MCP) within AWS WAF, a groundbreaking development in the sphere of API security. This functionality enables the identification and labeling of traffic directed toward MCP endpoints, blocking unauthorized MCP access and enhancing the visibility of MCP interactions. This level of insight allows security teams to gain a nuanced understanding of how AI agents interact with enterprise systems, which is crucial for effective threat management.

Furthermore, the solution introduces context-aware rate limiting capabilities, enabling organizations to apply intelligent thresholds to sensitive parameters, such as user IDs and email addresses. This feature is instrumental in preventing enumeration attacks and other forms of abuse. In addition to these protections, the ruleset enriches security telemetry by labeling critical request attributes, including authentication headers and user identifiers, thereby improving detection accuracy and augmenting downstream security analytics.

Roey Eliyahu, the CEO and co-founder of Salt Security, emphasized the transformative nature of AI agents in application development, stating, “AI agents are transforming how applications are built, and APIs are the layer where those agents act. By bringing Salt’s API and agentic security intelligence directly into an AWS WAF as managed rules, we’re providing every AWS customer with an easy way to deploy these new rules in minutes. This allows organizations to immediately identify and stop the API and AI agent threats that legacy rules were never designed to catch.”

Salt Security is also engaging with attendees at Black Hat USA 2026, inviting them to visit their booth (#5938) for an opportunity to request an Agentic Attack Assessment from Salt Labs researchers. Participants can witness demonstrations of the company’s Agentic Security Graph and experience the new AWS WAF managed ruleset in action.

The Salt Managed Rules for AWS WAF – AI Agent & API Security are now readily accessible through the AWS Marketplace across all commercial AWS Regions, as well as globally via Amazon CloudFront. Existing AWS WAF customers can subscribe to this ruleset and easily attach it to their existing web Access Control Lists (ACLs) from the AWS Management Console, streamlining the deployment process.

With the increasing reliance on APIs for various digital interactions and the burgeoning role of AI agents in automating processes, the introduction of Salt Security’s managed ruleset marks a pivotal moment in the domain of cybersecurity. By addressing the emerging threats associated with these technologies, Salt Security is positioning organizations to better safeguard their digital assets and maintain the integrity of their information systems in an ever-evolving threat landscape.

Source link

Exit mobile version