Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.

Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of

Google limits Meta’s use of its Gemini AI models

Google limits Meta’s use of its Gemini AI models Source: Hacker News