🔐 Security Pulse · 2026-09-07 16:00 UTC

⚡ TL;DR

Malware impersonating the Israeli government with a payload called “goop” targeting Israeli networks emerges as most critical event; multiple new CVEs disclosed in critical telecom and software infrastructure. Overall threat level remains elevated.

🔐 CYBER THREATS

  • 🔴🔴🔴 Malware identified masquerading as an Israel government domain (israel.gov.2026.vercel.app) deploying “goop” payload targeting Israeli government networks, with unclear objectives but potential espionage or disruption; observed by vxunderground [1] [2] [3].
  • 🟡⚠️ CVE-2026-86212 in Open5GS 2.7.7/2.8.0 AMF/MME component allows improper authorization manipulations threatening 5G telecom infrastructure security [4].
  • 🟡 CVE-2026-86242 in Bifrost HTTP transport allows unauthenticated plugin upload bypassing management authentication, risking server compromise [5].
  • 🟡 Multiple CVEs in PocketMine-MP prior versions (DoS, authentication bypass, validation flaws - CVE-2020-37277 to CVE-2022-51009) posing risks to game server stability and security [6] [7] [8] [9] [10].
  • 🟡 CVEs 86205, 86250, 86251, 86252, 86253 in h3 npm package affect versions before 2.0.1-rc.18, including path traversal, open redirect, cookie manipulation and header injection, risking Node.js web server integrity [12-16].
  • 🟡 CVEs 86254, 86255, 86256, 86257 affecting wger fitness app allow auth bypass, logic flaws in routine duration, open redirect, and spreadsheet formula injection, posing risks of data corruption and privilege abuse [17-19].
  • 🟡⚠️ Multiple SQL injection and authorization bypass vulnerabilities (CVE-2026-86223 to 86225, 86230+, 86213-86215) found in SourceCodester and Mstfakts College-Management-System, threatening educational institutions' data integrity [20-22][30-32].
  • 🔴 Data breach reported at Aesto Health involving exposure of sensitive health data, with good transparency and urgent notice issued by the company.

🛡️ NATIONAL SECURITY

  • 🟡 Malware campaign impersonating Israeli government infrastructure indicates hostile cyber espionage efforts likely targeting Israeli state networks [1] [2] [3].
  • 🟡 The evolving malware threat landscape with “goop” payloads and suspected radioactive-themed malware interest points to potential hybrid cyber-physical threat experimentation in private networks.

⚠️ RISK FLAGS

  • ⚠️🔴 Israeli government-targeting malware campaign using spoofed domains actively observed; immediate monitoring and mitigation needed due to potential espionage or disruption [1] [2] [3].
  • ⚠️ Emerging critical vulnerabilities in 5G telecom infrastructure (Open5GS CVE-2026-86212) could enable unauthorized access or disruption of mobile networks [4].
  • ⚠️ Aesto Health data breach with exposed sensitive medical data demands urgent containment and investigation to prevent identity theft or further leaks.

🧭 THREAT MOOD

Elevated 🟡 due to active targeted espionage malware, critical telecom vulnerabilities, and significant private sector data breach; no full-scale cyberwarfare or kinetic incidents detected but vigilance required.

📎 Sources

  1. Had to change some wording, some people thought this was malwa… — @vxunderground
  2. I looked at this goop masquerading as the Israel government. I… — @vxunderground
  3. I got some interesting goop (malware). To make a long story s… — @vxunderground
  4. CVE-2026-86212 A vulnerability has been found in Open5GS 2.7.7… — @CVEnew
  5. CVE-2026-86242 Bifrost HTTP transport before 2.0.0 accepts an … — @CVEnew
  6. CVE-2020-37277 PocketMine-MP versions before 3.15.4 contain a … — @CVEnew
  7. CVE-2021-48006 PocketMine-MP before 4.0.3 does not perform cas… — @CVEnew
  8. CVE-2021-48007 PocketMine-MP versions before 3.18.1 fail to va… — @CVEnew
  9. CVE-2022-51008 PocketMine-MP before 4.12.3 fails to limit unau… — @CVEnew
  10. CVE-2022-51009 PocketMine-MP before 4.7.2 fails to properly ha… — @CVEnew

Educational & informational only — not financial advice. Markets carry risk; do your own research.
Serial 20260907-16-v63 · 2026-09-07 16:00 UTC · pulse.uzylab.com