CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3329

As cited

Copy frozen at (site build).

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced will retire its Layer 7 automatic mitigation capability on January 1, 2027. The company is introducing an Anti-DDoS managed rule group to AWS WAF, initially deployed in Count mode to preserve traffic visibility alongside existing Layer 7 protection and WAF rules. The rule group is available to all AWS WAF customers and included with Shield Advanced subscriptions.

Why it matters: AWS Shield Advanced subscribers must plan migration from L7 automatic mitigation to the new Anti-DDoS managed rule group before the January 1, 2027 sunset date to maintain DDoS protection for web applications.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced will retire its layer 7 automatic mitigation on January 1, 2027. To ease the transition, AWS is adding an Anti-DDoS managed rule group to eligible web access control lists in Count mode, which operates alongside existing protections and is available to all AWS WAF customers.

Why it matters: AWS Shield Advanced subscribers must plan migration of their layer 7 distributed denial of service (DDoS) protections before the January 1, 2027 retirement date to avoid service gaps.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-DDoS managed rule group for application-layer protection in Count mode, which will run alongside existing mitigation features and AWS WAF rules. The company is retiring the previous L7 automatic mitigation on January 1, 2027, with a migration timeline beginning July 27, 2026. The new rule group applies to eligible web access control lists and is available to all AWS WAF customers, including Shield Advanced subscribers.

Why it matters: Organizations using AWS Shield Advanced must plan to migrate from L7 automatic mitigation to the new Anti-DDoS rule group before the January 1, 2027 deadline to maintain distributed denial of service (DDoS) protection for their applications.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is adding an Anti-DDoS managed rule group for application-layer distributed denial of service (DDoS) protection, initially deployed in Count mode to preserve traffic flow alongside existing mitigation rules. The service will retire its current L7 automatic mitigation on January 1, 2027, requiring customers to migrate to the new rule group during a transition period beginning July 27, 2026.

Why it matters: Organizations using AWS Shield Advanced must plan their DDoS protection migration before the January 1, 2027 retirement date to maintain Layer 7 attack defense capabilities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-DDoS managed rule group for application-layer (L7) distributed denial of service (DDoS) protection, initially deployed in Count mode to eligible web access control lists (ACLs). The company will retire existing Shield Advanced L7 automatic mitigation on January 1, 2027, requiring customers to migrate to the new rule group during a transition period starting July 27.

Why it matters: AWS Shield Advanced and Web Application Firewall (WAF) customers must plan migration from deprecated L7 automatic mitigation to the new Anti-DDoS rule group before the January 1, 2027 retirement date to maintain application DDoS protection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-DDoS managed rule group for application-layer protection in Count mode, which will run alongside existing Layer 7 automatic mitigation and AWS WAF rules. Starting January 1, 2027, AWS will retire the automatic mitigation capability and require customers to migrate to the new rule group. The transition preserves traffic visibility while shifting responsibility for manual response configuration to customers.

Why it matters: AWS Shield Advanced subscribers must plan migration before January 1, 2027, or lose automatic layer 7 distributed denial of service (DDoS) protection; teams need to configure the new Anti-DDoS rule group and update incident response procedures.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced will retire its automatic Layer 7 DDoS mitigation on January 1, 2027, and is introducing the Anti-DDoS managed rule group in Count mode as a migration path. The new rule group integrates with existing web access control lists and AWS Web Application Firewall (WAF) rules while maintaining traffic flow, and is available to all AWS WAF customers and included with Shield Advanced subscriptions.

Why it matters: AWS customers using Shield Advanced must plan for the retirement of automatic application-layer protections and test the new Anti-DDoS managed rule group before the deadline to avoid gaps in distributed denial of service (DDoS) defense.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-DDoS managed rule group for application-layer distributed denial of service (DDoS) protection, initially deployed in Count mode to preserve traffic flow alongside existing protections. The company will retire Shield Advanced's Layer 7 automatic mitigation on January 1, 2027, requiring customers to migrate to the new rule group.

Why it matters: AWS Shield Advanced subscribers must plan migration from automatic L7 DDoS mitigation to the new managed rule group before the January 2027 retirement date to maintain protection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-DDoS managed rule group for application-layer protection, initially deployed in Count mode to preserve traffic alongside existing defenses. The company will retire Shield Advanced's L7 automatic mitigation on January 1, 2027, requiring customers to migrate to the new rule group during the transition window.

Why it matters: AWS WAF and Shield Advanced customers must plan migration to the Anti-DDoS rule group before the January 1, 2027 retirement date to maintain application-layer distributed denial of service (DDoS) protection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-DDoS managed rule group for application-layer protection, initially deployed in Count mode to preserve traffic flow while running alongside existing protections. AWS will retire the current Shield Advanced Layer 7 automatic mitigation on January 1, 2027, requiring customers to migrate to the new rule group during the transition period.

Why it matters: Organizations using AWS Shield Advanced must plan migration to the new Anti-DDoS ruleset before the January 1, 2027 retirement date to maintain application-layer protection against distributed denial of service (DDoS) attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced will retire its Layer 7 automatic mitigation on January 1, 2027, and is introducing the Anti-DDoS managed rule group in Count mode to eligible web access control lists. The new rule group, available to all AWS WAF customers and included with Shield Advanced subscriptions, preserves traffic flow while running alongside existing Layer 7 automatic mitigation and AWS WAF rules.

Why it matters: AWS Shield Advanced subscribers must plan for the mitigation retirement and evaluate the Anti-DDoS managed rule group as a replacement to maintain distributed denial of service (DDoS) protection coverage before the January 1, 2027 deadline.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS is introducing an Anti-DDoS managed rule group for application-layer attack protection in AWS Web Application Firewall (WAF), initially deployed in Count mode to observe traffic without blocking. The company will retire the existing Shield Advanced L7 automatic mitigation on January 1, 2027, requiring customers to migrate to the new rule group.

Why it matters: AWS WAF and Shield Advanced customers must plan migration to the new Anti-DDoS rule group before the January 1, 2027 retirement date to maintain application-layer distributed denial of service (DDoS) protection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced will retire its layer 7 (L7) automatic mitigation on January 1, 2027. The company is introducing an Anti-DDoS managed rule group in Count mode to help customers transition, which runs alongside existing mitigation and web access control list (WAF) rules. The new rule group is available to all AWS WAF customers and included with Shield Advanced subscriptions.

Why it matters: AWS Shield Advanced subscribers must plan their migration away from L7 automatic mitigation before the January 1, 2027 deadline to maintain distributed denial of service (DDoS) protection for application traffic.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-distributed denial of service (DDoS) managed rule group for layer 7 (L7) application protection, initially running in Count mode alongside existing mitigation. AWS will retire the existing L7 automatic mitigation on January 1, 2027, requiring customers to migrate their configurations during the transition period.

Why it matters: Organizations using AWS Shield Advanced must plan migration of their L7 DDoS protections to the new Anti-DDoS rule group before the January 1, 2027 retirement date to maintain continuous application security.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS Shield Advanced is introducing an Anti-distributed denial of service (DDoS) managed rule group for layer 7 (L7) application protection, initially running in Count mode alongside existing mitigation. AWS will retire the existing L7 automatic mitigation on January 1, 2027, requiring customers to migrate their configurations during the transition period.

Why it matters: Organizations using AWS Shield Advanced must plan migration of their L7 DDoS protections to the new Anti-DDoS rule group before the January 1, 2027 retirement date to maintain continuous application security.

VendorsAmazon Web Services
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary