Security Briefing | June 26, 2026 - Critical Linux Kernel Flaw Grants Root Access, Miasma Malware Hits Go Ecosystem, Russian APT Deploys STOCKSTAY Backdoor
A critical Linux kernel privilege escalation vulnerability (CVE-2026-43503, CVSS 8.8) now has a public exploit walkthrough allowing local users to gain root access. The Miasma malware family has expanded its supply chain attack from npm into the Go ecosystem, abusing GitHub Actions workflows. Meanwhile, Russian state-sponsored group Turla has deployed a new .NET backdoor called STOCKSTAY against Ukrainian government and military targets.
By EACA Summit Content Team

1. Critical DirtyClone Linux Kernel Flaw Enables Local Privilege Escalation to Root
JFrog Security Research published a working exploit walkthrough for CVE-2026-43503 (CVSS 8.8), a Linux kernel privilege escalation vulnerability in the DirtyFrag family. The flaw allows a local user to corrupt file-backed memory through a cloned network packet and gain root access. The patch has been released.
Verified Facts
- CVE-2026-43503 is a Linux kernel privilege escalation vulnerability with CVSS score 8.8
- JFrog Security Research published a working exploit walkthrough on June 25, 2026
- The vulnerability allows local users to gain root privileges via cloned network packets
- A patch has been released
Evidence
- CVE-2026-43503
- JFrog Security Research exploit walkthrough
Impact
This vulnerability poses a direct risk to any Linux system where local users have access, enabling full system compromise. Defenders should prioritize patching and restrict local user access where possible.
Confidence Level: High
The Hacker News | BleepingComputer
2. Miasma Malware Expands to Go Ecosystem in Ongoing Supply Chain Attack
Cybersecurity researchers have identified new malicious npm packages (LeoPlatform, RStreams) and GitHub Actions workflow abuse linked to the Mini Shai-Hulud, Miasma, and Hades malware family. The campaign has now propagated to the Go ecosystem, indicating an expanding supply chain attack targeting developers.
Verified Facts
- New malicious npm packages LeoPlatform and RStreams have been identified
- GitHub Actions workflows are being abused as part of the campaign
- The malware family has expanded to target the Go ecosystem
- The activity is linked to the Mini Shai-Hulud, Miasma, and Hades malware family
Evidence
- Security research reports from The Hacker News and BleepingComputer
Impact
This supply chain attack threatens software development pipelines, potentially compromising downstream users. Developers should audit npm and Go dependencies and review GitHub Actions configurations.
Confidence Level: High
The Hacker News | BleepingComputer
3. Russian APT Turla Deploys STOCKSTAY Backdoor Against Ukrainian and Italian Targets

Google Threat Intelligence Group attributed a new .NET backdoor called STOCKSTAY to the Russian state-sponsored threat actor Turla. The backdoor has been deployed against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. The backdoor is described as continually developed by the group.
Verified Facts
- STOCKSTAY is a previously undocumented .NET backdoor attributed to Turla
- It has been used against government and military organizations in Ukraine
- Entities with an interest in Italian foreign policy have also been targeted
- Google Threat Intelligence Group published the findings on June 25, 2026
Evidence
- Google Threat Intelligence Group report
- SecurityWeek article
Impact
This backdoor represents a persistent threat to European government and military networks. Defenders should monitor for .NET-based backdoors and review network traffic for indicators of compromise associated with Turla.
Confidence Level: High
The Hacker News | SecurityWeek
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



