Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Aug 07, 2026
Endpoint Security / Vulnerability
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices, virtualization, containerization, and cloud infrastructure, including Windows, Linux, and macOS implementations. Two implementation-specific flaws have been assigned CVEs: CVE-2026-56181 (CVSS score: 8.3) in Windows NAT used by Hyper-V, and CVE-2026-63913 (CVSS score: 8.2) in Linux Netfilter conntrack. The attack model generally places an attacker-controlled system behind the same NAT infrastructure as the victim, while the exact capabilities and preconditions vary by technique and platform. The mitigation guidance therefore emphasizes separating untrusted workl...