AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful rules in both custom and managed rule groups, while stateless rules are not supported. The feature is enabled by defaul

Amazon Web Services (AWS) has introduced a new capability for its Network Firewall service, providing visibility into the hit counts of stateful firewall rules. This feature, which became available on August 24, 2026, is designed to help security teams identify unused or redundant rules, validate the effectiveness of security controls, and streamline incident response.
The rule hit count capability tracks how often stateful firewall rules match network traffic. The counter increments when a rule match generates an alert log. Rules configured with `alert`, `drop`, or `reject` actions automatically generate these logs. For rules with a `pass` action, the `alert` keyword must be included for them to appear in the metric. This functionality applies to stateful rules within both custom and managed rule groups; stateless rules are not supported.
AWS Network Firewall protects Amazon Virtual Private Clouds (VPCs) by enabling customers to create granular traffic control rules and utilize AWS-managed rules powered by Amazon threat intelligence. Its capabilities include geographic IP filtering, deep packet inspection, intrusion prevention, and proxy functionality.
The new feature is enabled by default and incurs no additional Network Firewall cost, though standard charges for storing and querying log data still apply. Rule hit counts are available in all AWS Regions where AWS Network Firewall is supported, with the exception of the Middle East (UAE and Bahrain) regions.
Organizations with governance policies that mandate the removal of dormant rules after a specified period have previously lacked a mechanism to identify them. Similarly, teams responsible for compliance frameworks such as PCI DSS 4.0 and the Digital Operational Resilience Act (DORA) often face challenges in providing evidence that specific security controls are actively functioning. The rule hit count data aims to address these issues by enabling the identification and removal of unused rules, accelerating incident response, and validating security control effectiveness for compliance purposes.
Rule group metadata is automatically included in firewall logs. This metadata is utilized by the Network Firewall monitoring dashboard to calculate hit counts, offering security teams a consolidated view of rule activity without requiring manual log queries. Users can also access and analyze this data by directly querying logs using CloudWatch Logs Insights for logs stored in CloudWatch, or Amazon Athena for logs stored in Amazon S3.
The Network Firewall dashboard now includes a "Top Rule Hits" view. This panel displays the most frequently triggered stateful rules over a selected period, detailing their hit counts, their share of overall activity, specific rule details, and the last time they occurred. Rules whose signature IDs do not appear in this metric have not matched traffic during the selected timeframe, potentially indicating a stale rule or an incorrect order within its rule group.
During incident response, this view can be particularly useful. For instance, if a rule detects traffic to an out-of-band application security testing (OAST) domain, which could signal attempted data exfiltration or an attacker validating a vulnerability, filtering the metric to the timeframe of a suspected incident can help analysts quickly identify relevant activity without manually parsing numerous log entries. AWS also demonstrated how hit counts can validate recently introduced controls, such as rules covering AI and machine learning domains or geofencing restrictions on outbound traffic, by showing that these rules were matching traffic as intended.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early