Ethical hacker @synackredteam. Working on software/electronics, AI and robotics projects @sodium_24. Former @DARPA challenge competitor. Opinions are my own.

Keller, TX
Thanks @SynackRedTeam and The Datatech Times! Glad to be able to share some more about this research.
Nice writeup from The Datatech Times on @malcolmst and his NatJack research. Stagg first discovered that NAT table entries could be corrupted or replaced while on assignment for the Synack Red Team. In his own words: “For a lot of business and enterprise customers, I would say the TCP and HTTP session hijacking techniques are the most dangerous, since a lot of internal network traffic is still unencrypted, and untrusted/trusted workloads often share the same NAT." Worth the read if you want the story behind the NatJack research: hubs.ly/Q04x8SM70
1
3
396
I have posted a white paper with additional technical details about the NatJack attack class on natjack.io. I hope this will be useful! #natjack
1
88
I updated natjack.io with a vendor patch status matrix based on my testing. I will continue to update this on a best-effort basis, but can't guarantee it will always contain the latest information. I hope it will be helpful though! #natjack
1
2
3
311
White paper still coming soon! I recently adopted a really sweet stay kitten, Albireo, so it got slightly delayed :). #natjack
1
82
First set of NatJack demo videos are now live, with demonstrations taking place against the Docker network bridge. White paper to follow soon! #natjack piped.video/watch?v=Mh1COblG…
1
2
245
I plan on posting a few demo videos and white paper with some more technical details later this week. Stay tuned! #natjack
2
2
249
For anyone looking for more technical details in the meantime, my Black Hat slides are available for download here: blackhat.com/us-26/briefings… . #BHUSA #BHUSA26 #natjack
110
A product patch status matrix will also be posted on natjack.io once I can audit it for accuracy. It will be updated on a best-effort basis and shouldn’t be considered an authoritative guide. #natjack
75
Microsoft patched and published CVE-2026-56179 which relates to NatJack today, affecting Hyper-V in an upstream spoofing configuration. I have updated natjack.io with the CVE. Thank you @msftsecresponse for your work mitigating this! msrc.microsoft.com/update-gu… #natjack
1
2
191
Malcolm Stagg retweeted
🚨 Another system behind the same NAT could hijack your connection. New NatJack attacks can redirect live TCP sessions, spoof DNS replies, expose victim IPs/ports, or cause DoS. The researcher tested 32 products/configs across 13 vendors; Windows and Linux flaws now have CVEs. How the attack works: thehackernews.com/2026/08/ne…
5
53
266
50,827
Malcolm Stagg retweeted
Happening NOW at #BlackHatUSA! @SynackRedTeam Researcher @malcolmst is revealing NatJack, a newly developed network address translation (NAT) table manipulation attack class effective against most virtual and physical network infrastructure performing NAT. Learn more about the new attack class here: hubs.ly/Q04s8ttV0
2
9
1,005
Malcolm Stagg retweeted
NatJack attack class exposes design flaw across decades of network infrastructure. #blackhat “A lot of networks are vulnerable to this, and you can’t always rely on the layer two isolations that are in place.." networkworld.com/article/420…
4
6
649
Although I don’t fully agree with implied attack preconditions and severity, I appreciate @msftsecresponse work to patch and publish CVE-2026-56181 yesterday! msrc.microsoft.com/update-gu…
2
1
775
I will discuss more about this and other issues during my Black Hat briefing, which is now scheduled as a live presentation on August 6 (10:15am in Oceanside D). Feel free to join in if you will be attending Black Hat this year!
1
2
121
Responses from several VDPs on this vulnerability class make me wonder if public disclosure is generally a better approach. It seems a number one vendor priority right now is finding ways to dismiss issues and avoid paying, or reducing severity rating, putting customers at risk.
1
3
226
I look forward to discussing the range of vendor responses during my talk at Black Hat. Despite following all responsible disclosure guidelines, this may include, unfortunately, live demos of vulnerabilities which have not been patched due to inappropriate vendor responses.
91
I’m excited to be presenting at Black Hat USA this year! My presentation is titled “Breaking Trust Boundaries: Exploiting Design Assumptions in Network Infrastructure” blackhat.com/us-26/briefings…
1
5
11
2,427
This will be available as an on-demand briefing to conference attendees, then later published on the YouTube channel. This research is currently under coordinated disclosure with multiple vendors affected. I’ll try to share more details closer to the conference.
1
180
At this point, there have been a large range of vendor reactions to this research, ranging from “intended design” and “totally bogus” to reports accepted at P1 priority. Still curious to see how it all unfolds in terms of vendor patches prior to disclosure.
137