Salt Security has launched what it claims is the industry's first AWS WAF managed ruleset built to protect both APIs and AI agents. Available through AWS Marketplace, the ruleset adds protections against credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT anomalies. A notable feature is claimed first-in-industry support for the Model Context Protocol (MCP) within AWS WAF, enabling identification and blocking of unauthenticated MCP traffic. The solution also introduces context-aware rate limiting and enriched security telemetry. It can be deployed directly from the AWS Management Console without additional infrastructure and is available across all commercial AWS regions and via Amazon CloudFront.
59 Impressions