CIO Influence
CIO Influence News Security

Salt Security Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

Webpuppies Becomes an AWS Select Tier Services Partner

Salt Security Launches the First MCP Server to Revolutionize API Security  in the Age of AI

Salt Security Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection. Announced at Black Hat USA 2026, Salt’s new managed ruleset extends AWS WAF with purpose-built protection against API abuse and AI agent-driven threats, including industry-first MCP awareness.

Salt Security, the leader in Agentic and API Security, announced the availability of Salt Managed Rules for AWS WAF in AWS Marketplace. Delivered through the AWS WAF Partner Managed Rules program, it is the first managed ruleset purpose-built to secure both APIs and the AI agents that drive them. AWS WAF customers can attach it to existing web ACLs directly from the AWS console and be protected in minutes, with no proxies, no traffic redirection, and no new infrastructure to operate.

At Black Hat USA 2026, visitors to Salt Security’s booth #5938 can request an Agentic Attack Assessment with Salt Labs researchers, see the Agentic Security Graph in action, and get a first look at the new AWS WAF managed ruleset.

APIs now power nearly every digital experience, and AI agents are rapidly becoming the fastest-growing source of API traffic. Traditional WAF rules were never designed to understand the behavioral nuances of APIs or the dynamic nature of AI-powered agents, leaving security teams with blind spots that existing tools do not cover. The recent Hugging Face incident illustrates exactly how that gap is being exploited. Salt’s managed ruleset closes those gaps inside the AWS WAF deployments customers already run.

Also Read: CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX

The Salt Managed Rules deliver:

Advanced API threat detection, blocking common and complex attack vectors including credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT-based anomalies.

Industry-first Model Context Protocol (MCP) awareness, identifying and labeling traffic from MCP endpoints, blocking unauthenticated MCP access, and providing deeper observability into MCP interactions in AWS WAF environments.

Context-aware rate limiting, with smart limits on sensitive parameters such as user IDs and email addresses to stop enumeration and abuse patterns.

Security signal enrichment, labeling critical request attributes (auth headers, user identifiers, GraphQL queries) to boost detection fidelity and downstream analytics.

“AI agents are transforming how applications are built, and APIs are the layer where those agents act,” said Roey Eliyahu, CEO and Co-founder of Salt Security. “By bringing Salt’s API and agentic security intelligence directly into an AWS WAF as managed rules, we’re giving every AWS customer an easy way to deploy these new rules in minutes, so organizations can immediately see and stop the API and AI agent threats that legacy rules were never built to catch.”

Catch more CIO Insights: What Does “Job-Ready” Really Mean in IT and Cybersecurity?

[To share your insights with us, please write to psen@itechseries.com ]

Related posts

Element Biosciences and DNAnexus Announce Collaboration to Advance Multi-Omics Analysis

PR Newswire

NTT Security Holdings 2023 Global Threat Intelligence Report Reveals Alarming Blurred Line Between Cyberthreats and Real-World Impact

PR Newswire

Prisma Cloud Launches ML-Powered Next-Generation Cloud Security Posture Management Capabilities, Helping Organizations Accelerate Cloud Adoption

CIO Influence News Desk