CYBERSECURITYTRACKER
TRACKING7,256 stories in this site build1,517 vulnerability news stories in this site build
Permanent story citation

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4040

As cited

Copy frozen at (site build).

threat intel

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

A security researcher unveiled NatJack, a novel attack class that exploits network address translation (NAT) connection state to hijack TCP sessions, spoof DNS responses, and expose mapped ports. The attack affects multiple independent NAT implementations, including Windows, and was presented at Black Hat USA 2026.

Why it matters: Network infrastructure teams and organizations relying on NAT for internal security should evaluate their implementations for susceptibility to session hijacking and DNS spoofing, as the attack impacts widely deployed systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

A security researcher unveiled NatJack, a novel attack class that exploits network address translation (NAT) connection state to hijack TCP sessions, spoof DNS responses, and expose mapped ports. The attack affects multiple independent NAT implementations, including Windows, and was presented at Black Hat USA 2026.

Why it matters: Network infrastructure teams and organizations relying on NAT for internal security should evaluate their implementations for susceptibility to session hijacking and DNS spoofing, as the attack impacts widely deployed systems.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary