Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and

Security researcher Malcolm Stagg has disclosed a novel class of attacks, dubbed NatJack, which exploits vulnerabilities in Network Address Translation (NAT) implementations to achieve various malicious outcomes. The research, presented at Black Hat USA 2026, details how these attacks can manipulate NAT connection state to hijack active TCP sessions, spoof DNS responses, expose internal mapped ports, and potentially exhaust NAT tables, leading to denial-of-service conditions.
The core mechanism of NatJack attacks involves manipulating the internal connection state maintained by NAT devices. When a NAT device translates private IP addresses and port numbers to public ones, it keeps a record of these mappings to ensure return traffic is routed correctly. NatJack exploits how some NAT implementations handle the creation and modification of these state entries. By sending specially crafted packets, an attacker can trick the NAT device into creating or altering existing translation entries, thereby redirecting traffic or associating legitimate connections with attacker-controlled endpoints.
One significant impact of NatJack is the ability to hijack active TCP sessions. An attacker could, for instance, inject packets into an ongoing connection by manipulating the NAT state to redirect subsequent packets of a legitimate session through an attacker-controlled host. This could allow for data interception, modification, or even full session takeover. Another reported capability is DNS spoofing, where an attacker could manipulate NAT tables to redirect DNS queries to a malicious server, leading to users being directed to phishing sites or receiving incorrect resource records.
The research also highlighted the potential for exposing mapped ports. NAT devices often perform port mapping to allow external access to internal services. NatJack could potentially exploit NAT state manipulation to reveal or alter these mappings, making internal services unexpectedly accessible or redirecting legitimate external access to an attacker. Furthermore, by rapidly creating and modifying NAT entries, an attacker could exhaust the NAT table resources, leading to a denial-of-service condition for all devices behind the NAT, as new connections would be unable to be established.
The findings are particularly concerning because the affected behavior was observed across independently developed NAT implementations. While specific vendors were not detailed beyond mentioning Windows, this suggests that the underlying vulnerabilities might stem from common design patterns or assumptions in how NAT state is managed, rather than isolated bugs in a single product. This broad applicability indicates a potentially widespread issue across various network devices and operating systems that implement NAT functionality.
Mitigation for this class of attack would typically involve robust validation of incoming packets before updating NAT connection state. Implementations should carefully scrutinize source and destination addresses, port numbers, and TCP sequence numbers to prevent unauthorized modification or creation of state entries. Regular patching of network devices and operating systems is crucial, as vendors release updates to address such vulnerabilities. Network administrators should also consider implementing stricter firewall rules and intrusion detection systems that can flag unusual NAT table activity.
The disclosure of NatJack underscores the ongoing challenges in securing fundamental network infrastructure components. As NAT remains a ubiquitous technology for conserving IPv4 addresses and providing a basic layer of network segmentation, vulnerabilities that manipulate its core functionality can have far-reaching implications. This research serves as a reminder that even long-standing and widely deployed technologies can harbor subtle flaws that, when exploited, can undermine network security and user privacy.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed