REDWOOD CITY, Calif., Aug. 06, 2026 (GLOBE NEWSWIRE) — Sy ack, the AI + huma pe et atio testi g platfo m fo co ti uous secu ity validatio , today a ou ced ew esea ch f om Sy ack Red Team membe Malcolm Stagg eveali g NatJack, a class of attacks that exploits lo g-held t ust assumptio s i etwo k add ess t a slatio impleme tatio s. Stagg p ese ted the fi di gs today at Black Hat USA 2026. Testi g ide tified affected behavio ac oss i depe de tly developed impleme tatio s, i cludi g Wi dows, Li ux a d macOS, a d two CVEs have bee assig ed to date.
Stagg co ducted the esea ch ove seve al yea s a d is joi tly c editi g Sy ack Red Team alo g with his ow esea ch ha dle Sodium-24, of SODIUM-24, LLC. The esea ch ide tifies fou disti ct tech iques attacke s ca use agai st NAT devices: hijacki g active TCP co ectio s, poiso i g DNS espo ses, ide tifyi g the po ts assig ed to othe co ectio s, a d fo ci g de ial of se vice by exhausti g a device’s NAT table. Two CVEs have bee assig ed to date (CVE-2026-56181, affecti g Mic osoft Wi dows NAT i Hype -V, a d CVE-2026-63913, affecti g the Li ux etfilte co t ack subsystem). Additio al ve do adviso ies o CVE assig me ts may follow as coo di ated disclosu e co ti ues. I depe de t testi g fou d the u de lyi g flaw p ese t ac oss NAT impleme tatio s f om multiple ve do s usi g e ti ely i depe de t codebases, i cludi g Wi dows, Li ux, a d macOS.
U like vul e abilities tied to a specific codi g e o , NatJack stems f om a desig assumptio , that devices sha i g a NAT table ca t ust o e a othe , that held fo most of the i te et’s histo y but o lo ge holds u de adve sa ial co ditio s. Because the flaw is behavio al athe tha sig atu e-based, it may ot show up i co ve tio al automated sca i g.
“Malcolm’s esea ch o NatJack shows why effective secu ity testi g must challe ge lo g-held desig assumptio s, ot o ly sea ch fo familia softwa e flaws,” said Ma k Kuh , co-fou de a d CTO of Sy ack. “That depth of huma c eativity is ce t al to the Sy ack Red Team. We’ e p oud to suppo t Malcolm’s esea ch a d help defe de s u de sta d a d add ess the isk.”
The e is o si gle patch fo NatJack. Available fixes, i cludi g a Li ux ke el patch (ke el 6.6.142 a d highe ) a d a F eeBSD update (15.0 a d highe ), aise the difficulty of exploitatio but do ot close the u de lyi g desig gap. Sy ack expects emediatio to u fold i c eme tally ac oss ve do s ove a exte ded pe iod, a d ecomme ds o ga izatio s p io itize e c ypti g t affic (i cludi g i te ally), segme ti g u t usted wo kloads away f om t usted o es, a d e abli g p otectio s such as IP Sou ce Gua d i the i te im. Full tech ical details a d mitigatio guida ce a e available i Sy ack’s secu ity esea ch epo t o NatJack.
Stagg joi ed the Sy ack Red Team i 2020 followi g his pe fo ma ce i DARPA’s Fi di g Exploits to Thwa t Tampe i g ha dwa e bug bou ty. His p evious esea ch i cludes a Mic osoft Remote Desktop Clie t RCE, CVE-2021-34535, a d Google Ch ome exte sio vul e ability CVE-2024-0333. Stagg discussed his NatJack esea ch a d path to the SRT o Sy ack’s We’ e I podcast.
Malcolm Stagg, Resea che , Sy ack Red Team, I depe de t Resea che , SODIUM-24, LLCB eaki g T ust Bou da ies: Exploiti g Desig Assumptio s i Netwo k I f ast uctu eBlack Hat USA, Thu sday, August 6, 10:15 a.m. PT (Ocea side D, Level 2)
Sy ack is the AI + huma pe et atio testi g platfo m fo co ti uous secu ity validatio . Sa a AI Pe testi g combi es age tic AI with the Sy ack Red Team, a igo ously vetted global commu ity of secu ity esea che s, to expa d testi g cove age a d p ove eal-wo ld exploitability. The Sy ack Platfo m gives o ga izatio s co t ol a d visibility ac oss testi g activity, validated fi di gs a d emediatio status. Sy ack suppo ts poi t-i -time a d co ti uous pe et atio testi g ac oss web applicatio s, APIs, mobile applicatio s, cloud a d host i f ast uctu e, i te al e vi o me ts a d AI o LLM systems. Fou ded by fo me NSA ope atives, Sy ack has e abled ea ly 10 millio hou s of secu ity testi g to p otect c itical assets ac oss e te p ise, public-secto a d highly egulated e vi o me ts. Lea mo e at sy ack.com a d o Li kedI .
A photo accompa yi g this a ou ceme t is available at https://www.globe ewswi e.com/NewsRoom/Attachme tNg/4f623f0c-7dac-4c9c-a964-35fea0d101db






 