Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection

Your WAF is doing its job. It's blocking SQLi, XSS, and the usual suspects. But here's the problem: it wasn't built for APIs, and it definitely wasn't built for AI agents. APIs now power nearly every digital experience. And AI agents — the automated systems that access your APIs at machine speed, at machine scale — are the fastest-growing source of that traffic.

Top Security Risks of AI Agents

AI agents are rapidly moving from experimental projects into everyday business operations. Unlike traditional AI systems that generate content or answer questions, AI agents can take action. They can call APIs, access applications, retrieve data, execute workflows, and make decisions with limited human intervention. That shift is creating a new security challenge for enterprises.

The EU AI Act: Compliance for Companies Serving the EU Market

The EU AI Act is a global business issue. Just like GDPR before it, it reaches beyond EU borders. If your organization does business in the EU, you are in scope. Full enforcement begins August 2, 2026, with fines of up to 35 million euros or 7% of global turnover for non-compliance.

The Hugging Face Incident Proved the Real AI Risk Is in the Action Layer

Last week, an AI system crossed a line many still considered theoretical. During an internal cybersecurity evaluation, OpenAI tested a combination of models, including GPT-5.6 Sol and a more capable pre-release model, on ExploitGym, a benchmark that measures whether agents can turn software vulnerabilities into working exploits. The models were run with reduced cyber refusals and without the production classifiers normally used to prevent high-risk cyber activity.

Understanding the Importance of MCP Security

AI agents are moving from experiments into production workflows, and the Model Context Protocol (MCP) is becoming the connective layer that enables those agents to access enterprise data, applications, APIs, repositories, and automation tools. That makes MCP powerful, but also security-critical. As organizations adopt agentic AI, they need to understand not only how MCP improves connectivity but also how it creates new visibility, governance, and attack-surface challenges.

From prompt to action: Al Security with Salt Security and CrowdStrike

As enterprises accelerate adoption of Generative AI, the security perimeter is rapidly expanding. This creates a new, largely unprotected attack surface: the Agentic Action Layer. In this on-demand webinar, @CrowdStrike and Salt Security introduce an AI-native security architecture that spans the full chain of intent-to-action. Learn how CrowdStrike Falcon AIDR protects the model runtime, prompts, inference, and LLM behavior, while Salt Security governs and defends the APIs, MCPs, and services where AI actions actually occur.

We Trained Cybersecurity Startups to Win POVs, Not Solve Problems

Cybersecurity has a strange problem. Everyone says they want to reduce risk. But too often, the way we evaluate products rewards something narrower: how quickly a vendor can show value in a POV. Can it deploy fast? Can it work agentless? Can it produce a clean report? Can it map to OWASP, NIST, the EU AI Act, or the latest framework? Can it check enough boxes in the RFP?