Threat Intelligence

NatJack Attacks Exploit NAT Tables to Hijack Connections and Spoof DNS

The Hacker News · 7 Aug 2026
Key Takeaway Keep your routers, firewalls, and network equipment firmware updated, and watch for vendor security advisories related to NAT handling following this disclosure.

Security researcher Malcolm Stagg has revealed a new class of network attacks called NatJack, presented at Black Hat USA 2026. These attacks work by manipulating how network address translation (NAT) systems track active connections. NAT is a common technology used in routers and firewalls to let multiple devices share a single internet connection, and it's used by nearly every small business network.

By interfering with NAT connection tracking, attackers can hijack active TCP sessions, spoof DNS responses to redirect users to malicious sites, expose internal port mappings that should remain hidden, and exhaust NAT tables to cause outages. The research found that this weakness affects multiple, independently developed NAT implementations, including systems running on Windows, suggesting the issue is widespread rather than limited to a single vendor's product.

Because NAT underpins so much everyday business networking, from office routers to firewalls and VPN gateways, this research is significant even though it's early-stage and mainly aimed at security professionals for now. Businesses should watch for vendor patches and guidance as more details and mitigations become available in the coming weeks.

NAT security network attacks DNS spoofing TCP hijacking Black Hat 2026

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.