Share:
How Salt Security Brings Agentic Security to AWS

TL;DR: AI agents can enter company systems using approved login details, then access restricted data or use tools beyond their assigned task. Traditional security tools may miss the risk because the access appears legitimate. Salt Security is addressing this gap at the API layer, where agents retrieve data and use software tools. Its new managed rules bring AI-agent and API protection into Amazon’s firewall, helping companies monitor and control what agents do after they gain access.

In July, OpenAI tested whether its AI agents could find security flaws in software. The agents were meant to remain inside a sealed environment. Instead, they found exposed credentials and entered Hugging Face, a platform where developers share AI models. One agent noted the attack might be unauthorized, but the agents kept going.

The break-in did not come from a human hacker. It came from AI software that could reach real systems but had no clear sense of where its task should end.

As AI moves from answering questions to taking actions, protecting the model is no longer enough. AI security also has to account for what agents can do once they have access. Companies need control over those actions, too.

Salt Security’s answer starts with APIs. Its new rules for Amazon’s web application firewall detect dangerous API and AI agent activity. That raises a bigger question for any company running agents: can API security stop an agent that already has valid credentials?

Why the Attack Was Hard to Catch

The details of the break-in show why that question matters. According to OpenAI’s account, one agent shared the exposed credentials with the rest of the group. The agents then used weak spots in how Hugging Face processed dataset files. Within days, they were running their own code on dozens of its servers.

Finding the attack was another matter. Hugging Face said early warning signs showed up across its security tools, but none was clear on its own. The full picture only emerged once those signals were pieced together. At OpenAI, the clue that finally triggered an investigation was a set of unusual API calls.

AI Agents are Becoming a New Kind of Enterprise User

APIs are the connections that let one application request data or actions from another. Michael Callahan, chief marketing officer at Salt Security, explains why they matter so much for agents:

Snapshot of a quote by Michael Callahan, chief marketing officer at Salt Security

The tricky part is telling safe calls from harmful ones. An agent using approved credentials to reach an approved system can look completely legitimate, even when what it is doing is not. A successful login only tells you that an agent has access. It doesn’t tell you whether the next action makes sense. 

That is the problem AI agent security now has to solve: not just who can get in, but what they can do once they’re there.

That gap shows up clearly in Salt’s 1H 2026 research. It found that 99% of the attack attempts its researchers analyzed came from authenticated sources. Salt says those sources increasingly include AI agents with valid credentials but no human oversight or behavioral limits.

Security is Now Deciding How Far Agent Projects Go

The number of agents inside companies is climbing fast. Gravitee’s survey of 750 senior technology leaders found the average agent count roughly doubled in four months. The share being monitored, though, barely moved. That left about 48% of agents already in use unsecured.

Callahan links the gap to how quickly software now gets built. With AI coding tools, he says, developers can ship new features in hours instead of weeks. By the time security teams review that work, the agents and permissions involved can be hard to trace.

And that is starting to show up in buying decisions, too. In an Okta survey, 69% of respondents said security concerns are slowing their adoption of AI agents. Security has become part of the business case, deciding whether a promising pilot gets trusted with customers or sensitive data.

MCP is Making Agents More Useful and Harder to Track

The Model Context Protocol, or MCP, gives AI agents a standard way to plug into a company’s apps and data. That makes agents more useful, but it also gives them more places to connect. Each MCP server gives an agent another connection into company systems, creating another entry point for security teams to track and protect.

However, many of these servers are unprotected. A May 2026 study of 7,973 publicly reachable MCP servers found that about 40% let anyone use their tools without logging in.

Salt’s API security work has also focused on shadow APIs, the connections developers put into use without security teams knowing.

Callahan sees a familiar pattern here:

Snapshot of a quote by Michael Callahan, chief marketing officer at Salt Security

Salt’s platform is built to find agents across a company, along with the MCP servers and APIs they use. It scans company code and cloud settings, then watches activity as it happens to see how those pieces connect. This is where agentic security moves beyond simply knowing which agents exist to understanding what they can reach and what they do. The company calls the resulting map its Agentic Security Graph.

Salt says its system draws on eight years of enterprise API traffic. The idea is to use that history to spot agents pulling data in bulk or reaching for tools outside their role.

The AWS Launch is Also a Distribution Strategy

AWS WAF, Amazon’s web application firewall, screens traffic before it reaches a company’s apps and APIs. Customers can add Salt’s managed rules to their existing firewall from their AWS account, without rerouting traffic or running new systems.

The rules detect attacks such as repeated password guessing and block attempts to reach MCP servers without authentication. They also tag details like user IDs, giving investigators more context.

Salt doesn’t present those rules as the whole answer. It treats them as a first layer of defense. According to Callahan:

Snapshot of a quote by Michael Callahan, chief marketing officer at Salt Security

For Salt, the launch is also a faster route to buyers. Because the rules sit on AWS Marketplace, companies can buy them with the AWS budgets and approvals they already have.

Salt Bets That Security Starts After Login

Reaching buyers through AWS matters because Salt is not moving into an empty market. API security has already drawn in bigger players. Akamai completed its acquisition of Noname Security for about $450 million in 2024, and Harness merged with Traceable in 2025. Both deals folded API security into larger platforms.

Salt’s approach is a little different. Instead of asking customers to deploy another security layer, it is putting its protection into tools companies already use, including Amazon’s firewall.

AI agents will keep gaining access to more tools, because access is what makes them valuable. The hard part is letting them keep that access without trusting every action they take.

Salt is betting the API becomes the place where enterprises draw that line. If that bet is right, the most important security decision about an agent may come after it logs in.