- AWS WAF introduces the Salt Security managed rule group for out‑of‑the‑box API, AI agent, and Model Context Protocol (MCP) threat detection.
- The rule group automatically detects and mitigates API attacks (e.g., credential brute force, SSRF, GraphQL abuse, JWT anomalies) and labels/limits MCP traffic without custom rule writing.
- Available via AWS Marketplace with versioning support; users can add it to a Web ACL directly in the console with no additional configuration.