Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

AWS WAF now supports a Salt Security managed rule group for API and MCP threat detection

Дата публикации: 06-08-2026 21:10:00

AWS WAF now supports the Salt Security managed rule group, available through AWS Marketplace: Salt Managed Rules for AWS WAF - AI Agent & API Security. This rule group gives AWS WAF customers detection and mitigation for API-focused attacks and for traffic from AI agents and Model Context Protocol (MCP) endpoints, without writing or maintaining custom rules.

The rule group detects common and complex API attack vectors, including credential brute force, excessive GraphQL queries, server-side request forgery (SSRF), prototype pollution, and JSON Web Token (JWT) anomalies. It identifies and labels traffic from Model Context Protocol (MCP) endpoints, blocks unauthenticated MCP access, and adds observability into MCP interactions in AWS WAF. The rule group also applies rate limiting to sensitive request parameters, such as user identifiers and email addresses, to help mitigate enumeration and abuse. To support detection and downstream analysis, it labels request attributes including authorization headers, user identifiers, and GraphQL queries.

You can subscribe to the rule group and add it to a web ACL directly in the AWS WAF console through AWS Marketplace, with no additional configuration. The rule group supports versioning, and pricing is set by Salt Security through AWS Marketplace. For a full list of supported Regions, visit the AWS Regional Services page.

To get started, visit the AWS WAF console or find the Salt Security rule group in AWS Marketplace. For more information, see the AWS WAF Developer Guide.

Основное содержимое страницы с новостью.

AWS WAF now supports the Salt Security managed rule group, available through AWS Marketplace: Salt Managed Rules for AWS WAF - AI Agent & API Security. This rule group gives AWS WAF customers detection and mitigation for API-focused attacks and for traffic from AI agents and Model Context Protocol (MCP) endpoints, without writing or maintaining custom rules.

The rule group detects common and complex API attack vectors, including credential brute force, excessive GraphQL queries, server-side request forgery (SSRF), prototype pollution, and JSON Web Token (JWT) anomalies. It identifies and labels traffic from Model Context Protocol (MCP) endpoints, blocks unauthenticated MCP access, and adds observability into MCP interactions in AWS WAF. The rule group also applies rate limiting to sensitive request parameters, such as user identifiers and email addresses, to help mitigate enumeration and abuse. To support detection and downstream analysis, it labels request attributes including authorization headers, user identifiers, and GraphQL queries.

You can subscribe to the rule group and add it to a web ACL directly in the AWS WAF console through AWS Marketplace, with no additional configuration. The rule group supports versioning, and pricing is set by Salt Security through AWS Marketplace. For a full list of supported Regions, visit the AWS Regional Services page.

To get started, visit the AWS WAF console or find the Salt Security rule group in AWS Marketplace. For more information, see the AWS WAF Developer Guide.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AWS Network Firewall Now Supports Stateful Rule Hit Counts 021.217-08-2026
2AWS Security Agent now supports email-based MFA for penetration testing08.7806-08-2026
3Amazon Cognito now available as a skill in the Agent Toolkit for AWS08.707-08-2026
4AgentCore payments is now generally available in Amazon Bedrock AgentCore05.4518-08-2026
5AWS Clean Rooms supports minimum aggregation thresholds in custom analysis rules06.0613-08-2026
6Amazon S3 adds additional policy details to access denied error messages06.1813-08-2026
7AWS Marketplace now supports category-based notification subscriptions and multi-channel delivery for buyers0710-08-2026
8Amazon OpenSearch UI now supports Network Access Control05.1606-08-2026
9Securing What’s Next: Why Cisco on AWS Marketplace Is the Smartest Path Forward06.7615-06-2026
10AWS Marketplace now lets sellers configure net payment terms on private offers05.5306-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 6.5. Источник: aws.amazon.com.