ITSecurityGuru

Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection


Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF) capabilities to address emerging threats driven by agentic AI.

Announced at Black Hat USA 2026, the new Salt Managed Rules for AWS WAF are now available through AWS Marketplace as part of the AWS WAF Partner Managed Rules programme. The offering enables AWS customers to deploy enhanced API and AI agent protections directly from the AWS console without requiring additional infrastructure, proxies or traffic redirection.

The launch comes as organisations increasingly rely on APIs to power digital services while AI agents rapidly emerge as one of the fastest-growing sources of API traffic. According to Salt Security, traditional WAF rulesets lack the contextual awareness needed to identify API-specific attacks and the behavioural patterns associated with autonomous AI agents, creating new security blind spots.

The new managed ruleset is designed to address these challenges by providing advanced protection against common API attack techniques, including credential brute force attacks, excessive GraphQL queries, server-side request forgery (SSRF), prototype pollution and JWT-based anomalies.

A key differentiator is what Salt describes as the industry’s first support for the Model Context Protocol (MCP) within AWS WAF. The ruleset can identify and label traffic destined for MCP endpoints, block unauthenticated MCP access and improve visibility into MCP interactions, giving security teams greater insight into how AI agents are communicating with enterprise systems.

The solution also introduces context-aware rate limiting, allowing organisations to apply intelligent thresholds to sensitive parameters such as user IDs and email addresses to help prevent enumeration attacks and abuse. In addition, it enriches security telemetry by labelling important request attributes, including authentication headers, user identifiers and GraphQL queries, to improve detection accuracy and downstream security analytics.

“AI agents are transforming how applications are built, and APIs are the layer where those agents act,” said Roey Eliyahu, CEO and Co-founder of Salt Security. “By bringing Salt’s API and agentic security intelligence directly into an AWS WAF as managed rules, we’re giving every AWS customer an easy way to deploy these new rules in minutes, so organisations can immediately see and stop the API and AI agent threats that legacy rules were never built to catch.”

Visitors to Salt Security’s booth (#5938) at Black Hat USA 2026 can request an Agentic Attack Assessment from Salt Labs researchers, view demonstrations of the company’s Agentic Security Graph and see the AWS WAF managed ruleset in action.

The new Salt Managed Rules for AWS WAF – AI Agent & API Security are available immediately through AWS Marketplace across all commercial AWS Regions, as well as globally via Amazon CloudFront. Existing AWS WAF customers can subscribe to the ruleset and attach it directly to their existing web ACLs from the AWS Management Console.

The post Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection appeared first on IT Security Guru.



Source link