International Cyber Expo International Cyber Expo
  • About Us
Saturday, 19 September, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection

Announced at Black Hat USA 2026, the new managed ruleset brings purpose-built protection against API abuse and AI agent threats directly into AWS WAF.

by Guru Writer
August 5, 2026
in Editor's News
Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
Share on FacebookShare on Twitter

Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF) capabilities to address emerging threats driven by agentic AI.

Announced at Black Hat USA 2026, the new Salt Managed Rules for AWS WAF are now available through AWS Marketplace as part of the AWS WAF Partner Managed Rules programme. The offering enables AWS customers to deploy enhanced API and AI agent protections directly from the AWS console without requiring additional infrastructure, proxies or traffic redirection.

The launch comes as organisations increasingly rely on APIs to power digital services while AI agents rapidly emerge as one of the fastest-growing sources of API traffic. According to Salt Security, traditional WAF rulesets lack the contextual awareness needed to identify API-specific attacks and the behavioural patterns associated with autonomous AI agents, creating new security blind spots.

The new managed ruleset is designed to address these challenges by providing advanced protection against common API attack techniques, including credential brute force attacks, excessive GraphQL queries, server-side request forgery (SSRF), prototype pollution and JWT-based anomalies.

A key differentiator is what Salt describes as the industry’s first support for the Model Context Protocol (MCP) within AWS WAF. The ruleset can identify and label traffic destined for MCP endpoints, block unauthenticated MCP access and improve visibility into MCP interactions, giving security teams greater insight into how AI agents are communicating with enterprise systems.

The solution also introduces context-aware rate limiting, allowing organisations to apply intelligent thresholds to sensitive parameters such as user IDs and email addresses to help prevent enumeration attacks and abuse. In addition, it enriches security telemetry by labelling important request attributes, including authentication headers, user identifiers and GraphQL queries, to improve detection accuracy and downstream security analytics.

“AI agents are transforming how applications are built, and APIs are the layer where those agents act,” said Roey Eliyahu, CEO and Co-founder of Salt Security. “By bringing Salt’s API and agentic security intelligence directly into an AWS WAF as managed rules, we’re giving every AWS customer an easy way to deploy these new rules in minutes, so organisations can immediately see and stop the API and AI agent threats that legacy rules were never built to catch.”

Visitors to Salt Security’s booth (#5938) at Black Hat USA 2026 can request an Agentic Attack Assessment from Salt Labs researchers, view demonstrations of the company’s Agentic Security Graph and see the AWS WAF managed ruleset in action.

The new Salt Managed Rules for AWS WAF – AI Agent & API Security are available immediately through AWS Marketplace across all commercial AWS Regions, as well as globally via Amazon CloudFront. Existing AWS WAF customers can subscribe to the ruleset and attach it directly to their existing web ACLs from the AWS Management Console.

ShareTweet
Previous Post

Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw

Next Post

Kill switch fears now rival ransomware as a top security risk for European businesses, Proton study finds

Recent News

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor

Filigran Backs Security Serious Unsung Heroes Awards as New Sponsor

September 18, 2026
Four AI Agent Security Risks Organisations Can’t Afford to Ignore

Four AI Agent Security Risks Organisations Can’t Afford to Ignore

September 18, 2026
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

September 17, 2026
When Everyday Habits Become an Invisible Security Risk

When Everyday Habits Become an Invisible Security Risk

September 17, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol