What's Happening?
Security researcher Malcolm Stagg has unveiled a new class of attacks, termed NatJack, which exploit network address translation (NAT) tables to hijack TCP sessions and spoof DNS responses. Presented at Black Hat USA 2026, the research identified vulnerabilities
in both Windows and Linux systems, with specific CVEs assigned to flaws in Windows NAT and Linux Netfilter conntrack. The attacks require privileged access to a system behind the same NAT as the victim, emphasizing the need for separating untrusted workloads from trusted systems.
Why It's Important?
The NatJack attacks highlight significant vulnerabilities in NAT implementations, which are widely used in network infrastructure. These vulnerabilities could lead to unauthorized access and data breaches, posing a threat to organizations relying on NAT for network security. The research underscores the importance of applying security updates and implementing additional measures, such as IP Source Guard, to protect against such attacks. The findings also call attention to the need for continuous security assessments and improvements in network protocols to prevent exploitation.








