HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

NatJack Attack Class Hijacks TCP Sessions and Spoofs DNS by Manipulating NAT Tables

Researchers disclosed NatJack, a technique that corrupts NAT state tables to hijack active TCP connections and inject spoofed DNS responses. The flaw affects multiple NAT implementations and highlights a control gap that SOC 2 auditors will scrutinize for continuous monitoring and evidence collection.

LiveThreat™ Intelligence · 📅 August 07, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

NatJack Attack Class Hijacks TCP Sessions and Spoofs DNS by Manipulating NAT Tables

What Happened — Security researcher Malcolm Stagg disclosed a new attack class, NatJack, that corrupts NAT connection‑state tables to hijack live TCP sessions, inject spoofed DNS responses, expose internal port mappings, and exhaust NAT resources. The technique works against multiple, independently developed NAT implementations, including Windows built‑in NAT and several open‑source routers.

Why It Matters for Compliance & Audit Readiness

  • NAT manipulation bypasses network segmentation controls that SOC 2 CC6 (System Operations) expects to be continuously monitored and logged.
  • Spoofed DNS can undermine the integrity of data in transit, a direct violation of the SOC 2 CC5 (Security) principle of protecting communications.
  • Demonstrates a control‑gap where evidence of NAT‑state changes is rarely collected, highlighting the need for continuous control mapping and audit‑ready evidence.

Who Is Affected — Enterprises that rely on NAT for cloud‑front, remote‑access VPNs, or on‑premise edge routing; broadly spans technology, finance, healthcare, and retail sectors.

Recommended Actions

  • Inventory all NAT devices (Windows, Linux iptables, commercial routers) and map them to SOC 2 CC6/CC7 controls.
  • Enable detailed NAT‑state logging and forward logs to a SIEM for real‑time anomaly detection.
  • Deploy continuous configuration monitoring to detect unexpected NAT‑table changes.
  • Incorporate NAT‑state change logs into your audit evidence repository to satisfy SOC 2 “monitoring and logging” requirements.

Source: The Hacker News

Technical Notes — NatJack exploits the lack of integrity checks on NAT connection‑state entries, allowing an attacker with network‑level access to overwrite entries, hijack TCP streams, and forge DNS replies. No CVE has been assigned yet; the research was presented at Black Hat USA 2026.

📰 Original Source
https://thehackernews.com/2026/08/new-natjack-attacks-hijack-tcp-sessions.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →