@malcolmsti
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Ethical hacker @synackredteam. Working on software/electronics, AI and robotics projects @sodium_24. Former @DARPA challenge competitor. Opinions are my own.
Keller, TX
Joined June 2009
- Tweets185
- Following252
- Followers502
- Likes2.4K
Thanks @SynackRedTeam and The Datatech Times! Glad to be able to share some more about this research.
Nice writeup from The Datatech Times on @malcolmst and his NatJack research. Stagg first discovered that NAT table entries could be corrupted or replaced while on assignment for the Synack Red Team.
In his own words: “For a lot of business and enterprise customers, I would say the TCP and HTTP session hijacking techniques are the most dangerous, since a lot of internal network traffic is still unencrypted, and untrusted/trusted workloads often share the same NAT."
Worth the read if you want the story behind the NatJack research: hubs.ly/Q04x8SM70
I have posted a white paper with additional technical details about the NatJack attack class on natjack.io. I hope this will be useful! #natjack
I updated natjack.io with a vendor patch status matrix based on my testing. I will continue to update this on a best-effort basis, but can't guarantee it will always contain the latest information. I hope it will be helpful though! #natjack
White paper still coming soon! I recently adopted a really sweet stay kitten, Albireo, so it got slightly delayed :). #natjack
First set of NatJack demo videos are now live, with demonstrations taking place against the Docker network bridge. White paper to follow soon! #natjack youtube.com/watch?v=Mh1COblG…
I plan on posting a few demo videos and white paper with some more technical details later this week. Stay tuned! #natjack
For anyone looking for more technical details in the meantime, my Black Hat slides are available for download here: blackhat.com/us-26/briefings… . #BHUSA #BHUSA26 #natjack
A product patch status matrix will also be posted on natjack.io once I can audit it for accuracy. It will be updated on a best-effort basis and shouldn’t be considered an authoritative guide. #natjack
Microsoft patched and published CVE-2026-56179 which relates to NatJack today, affecting Hyper-V in an upstream spoofing configuration. I have updated natjack.io with the CVE. Thank you @msftsecresponse for your work mitigating this! msrc.microsoft.com/update-gu… #natjack
Great to see these proactive mitigations @geteero 👍 eero.com/blog/articles/prote…
Malcolm Stagg retweeted
🚨 Another system behind the same NAT could hijack your connection.
New NatJack attacks can redirect live TCP sessions, spoof DNS replies, expose victim IPs/ports, or cause DoS. The researcher tested 32 products/configs across 13 vendors; Windows and Linux flaws now have CVEs.
How the attack works: thehackernews.com/2026/08/ne…
Happening NOW at #BlackHatUSA! @SynackRedTeam Researcher @malcolmst is revealing NatJack, a newly developed network address translation (NAT) table manipulation attack class effective against most virtual and physical network infrastructure performing NAT.
Learn more about the new attack class here: hubs.ly/Q04s8ttV0
Malcolm Stagg retweeted
NatJack attack class exposes design flaw across decades of network infrastructure. #blackhat
“A lot of networks are vulnerable to this, and you can’t always rely on the layer two isolations that are in place.."
networkworld.com/article/420…
Although I don’t fully agree with implied attack preconditions and severity, I appreciate @msftsecresponse work to patch and publish CVE-2026-56181 yesterday!
msrc.microsoft.com/update-gu…
Responses from several VDPs on this vulnerability class make me wonder if public disclosure is generally a better approach. It seems a number one vendor priority right now is finding ways to dismiss issues and avoid paying, or reducing severity rating, putting customers at risk.
I’m excited to be presenting at Black Hat USA this year! My presentation is titled “Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure” blackhat.com/us-26/briefings…
This will be available as an on-demand briefing to conference attendees, then later published on the YouTube channel. This research is currently under coordinated disclosure with multiple vendors affected. I’ll try to share more details closer to the conference.