<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dns-Spoofing on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dns-spoofing/</link><description>Recent content in Dns-Spoofing on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 07 Aug 2026 11:54:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dns-spoofing/index.xml" rel="self" type="application/rss+xml"/><item><title>NatJack: NAT Manipulation Enables TCP Hijack and DNS Spoofing</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-new-natjack-attacks-hijack-tcp-sessions-and-spoof-dns-by-man/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-new-natjack-attacks-hijack-tcp-sessions-and-spoof-dns-by-man/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel attack class affecting multiple NAT implementations including Windows — no active exploitation or patches announced yet, so monitor for vendor advisories and evaluate whether firewall rule hardening or NAT timeout tuning applies to your perimeter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> NatJack introduces TCP session hijacking and DNS spoofing via NAT state manipulation; no IOCs or ATT&amp;amp;CK-mapped TTPs are available yet, so track for detection research as the community digests the Black Hat presentation.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>