importantSYS.SOURCE: The Hacker News• 2026-08-07T15:02:57+05:30
NatJack Attack Exploits NAT Table Manipulation to Hijack TCP Sessions and Spoof DNS
NatJack is a new attack that exploits vulnerabilities in NAT table manipulation to hijack TCP sessions and spoof DNS responses, affecting Windows and Linux systems. It highlights the need for network segmentation, encryption, and applying patches for CVE-2026-56181 and CVE-2026-63913.
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.
Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and
*** END OF TRANSMISSION ***