New 'NatJack' Attacks Exploit NAT Tables to Hijack TCP Sessions and Spoof DNS

AI-generated NewsSnap summary based on source reporting.
Published: 2026-08-07
Category: technology
Source: The Hacker News

Security researcher Malcolm Stagg has disclosed a new class of attacks, dubbed 'NatJack,' which manipulate Network Address Translation (NAT) connection states to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. The research, presented at Black Hat USA 2026, identified implementation-specific flaws with assigned CVEs (CVE-2026-56181 for Windows NAT and CVE-2026-63913 for Linux Netfilter conntrack), emphasizing the need for separating untrusted workloads behind shared NAT infrastructure.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai