← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 6, 2026 · 18:55via CSO Online

NatJack exploits put NAT security assumptions to the test at Black Hat

Brief

For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability.

The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was). At Black Hat USA 2026 , researcher Malcolm Stagg , an independent researcher and Synack Red Team member, disclosed NatJack, an attack class that manipulates the NAT connection tracking table.

An attacker sharing a NAT boundary with a victim can hijack active connections, poison DNS responses, and force denial of service , without the IP spoofing or broadcast domain access older Layer 2 attacks required. Thirteen vendors were notified, and testing covered 32 products and configurations across 95 reports.

Read more on CSO Online