Synack Red Team’s Malcolm Stagg Details NatJack on NAT
5th article in the last 90 days, one of 7 articles referencing Synack. Previous coverage: Synack Red Team researcher Malcolm Stagg presents NatJack attack class (Aug 2026).
Companies mentioned
Best suited for
- Seniority
- C Level / Executive Team
- Job function
- Chief Information Security Officer
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Adopters
- Technology maturity
- Emerging Exploration
- Industry
- Information Technology / Software & Services / IT Services / Cloud Services
Our classification, not the publisher's statement. Best suited for, not only for.
Synack Red Team researcher Malcolm Stagg presented research on NatJack, an attack class that targets design assumptions in network address translation (NAT) implementations. The research matters because it links exploitation paths to behavioral trust assumptions in how NAT devices handle shared state.
Stagg’s testing identified affected behavior across independently developed NAT implementations, including Windows, Linux and macOS. Two CVEs were assigned to date. The work described NatJack as distinct from vulnerabilities tied to a specific coding error.
According to the research, NatJack stems from a design assumption that devices sharing a NAT table can trust one another. Because the flaw is behavioral rather than signature-based, the report states it may not appear in conventional automated scanning. The research identifies four techniques attackers can use against NAT devices: hijacking active TCP connections, poisoning DNS responses, identifying ports assigned to other connections, and forcing denial of service by exhausting a device’s NAT table.
Synack stated there is no single patch for NatJack. The company cited fixes that include a Linux kernel patch (kernel 6.6.142 and higher) and a FreeBSD update (15.0 and higher), which it said raise the difficulty of exploitation without closing the underlying design gap. Synack said remediation would unfold incrementally across vendors over an extended period and recommended organizations prioritize encrypting traffic (including internally), segmenting untrusted workloads away from trusted ones, and enabling protections such as IP Source Guard in the interim.
“Malcolm’s research on NatJack shows why effective security testing must challenge long-held design assumptions, not only search for familiar software flaws,” said Mark Kuhr, co-founder and CTO of Synack. “That depth of human creativity is central to the Synack Red Team. We’re proud to support Malcolm’s research and help defenders understand and address the risk.”
Additional vendor advisories or CVE assignments may follow as coordinated disclosure continues.
Press release, provided by Globe Newswire on behalf of Synack. Read the original.