AWS WAF Gets AI-Powered API Security with Salt Security Rules
AWS WAF now integrates Salt Security's managed rule group through AWS Marketplace, giving you out-of-the-box detection for API attacks, AI agent traffic, and Model Context Protocol (MCP) endpoints—no custom rules needed. The ruleset catches nasty stuff like credential brute force, GraphQL abuse, SSRF, and JWT anomalies while adding smart rate limiting on sensitive parameters.
source: [aws/whats-new]