AWS said Shield Advanced is shifting its application-layer automatic mitigation into the AWS WAF Anti-DDoS managed rule group, starting with automatic additions in Count mode for eligible web ACLs between July 27 and August 7, 2026. The new AWS WAF-based protection is designed to improve Layer 7 DDoS response with faster profiling and mitigation, support for Block, Count, and Challenge actions, lower web ACL capacity use from 150 WCU to 50 WCU, and richer visibility through dashboards, labels, and CloudWatch and AWS WAF metrics.
AWS said existing Shield Advanced automatic mitigation will remain active during the transition, but the legacy application-layer feature will be retired on January 1, 2027. Customers that do not migrate by then will lose automatic Layer 7 DDoS protection, while eligible configurations may be auto-upgraded beginning October 1, 2026 and receive temporary fee and WCU waivers during the evaluation period through September 30, 2026. AWS also warned customers using infrastructure-as-code and AWS Firewall Manager to update policies and definitions so application-layer protections continue after the migration.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
AWS said Shield Advanced application-layer automatic mitigation will sunset on 2027-01-01. Customers that have not migrated by that date will lose automatic Layer 7 DDoS mitigation.
AWS announced that beginning on 2026-07-27 it would start automatically adding the AWS WAF Anti-DDoS managed rule group in Count mode to eligible Shield Advanced web ACLs as part of a phased migration of Layer 7 DDoS protection. The rollout was described as occurring between July 27 and August 7, 2026, while existing Shield Advanced automatic mitigation remains active during the transition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.