
Today's Top Cybersecurity News – February 17, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. CVE-2026-2553: SQL Injection in tushar-2223 Hotel-Management-System home.php A remote SQL injection vulnerability exists in the HTTP POST handler of the tushar-2223 Hotel-Management-System's home.php file. Manipulating the Name or Email parameters allows attackers to execute arbitrary SQL commands. The exploit is publicly available, increasing the risk of active attacks. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2553 3. Malicious Chrome Extension Steals 2FA and Analytics from Facebook Business Manager A deceptive Chrome extension posing as a Meta Business Suite productivity tool is actively stealing Two-Factor Authentication (2FA) seeds, one-time codes, and sensitive business analytics from Facebook Business Manager accounts. This exposes users to account takeover risks despite the presence of 2FA protections. Sources: Gbhackers, Therecord https://gbhackers.com/malicious-chrome-extension-exposes-facebook-manager/ 4. Lotus Blossom Hackers Compromise Notepad++ Update Infrastructure for Espionage Between June and December 2025, the state-sponsored Lotus Blossom group breached the official Notepad++ update hosting infrastructure, enabling them to deliver malicious payloads through trusted developer tool updates. This compromise poses significant risks to users by turning a widely used software update channel into an espionage vector. Sources: Cvefeed, Gbhackers https://gbhackers.com/notepad-breached/ 5. Multiple Remote Code Execution and Injection Vulnerabilities Disclosed in Popular Software Several critical and medium severity vulnerabilities have been disclosed affecting multiple software products including LigeroSmart, yued-fe LuLu UI, vichan-devel, Comfast CF-E4, and others. These include remote code execution via command injection, cross-site scripting, and unverified password changes, with some exploits publicly available, increasing the risk of active attacks. Sources: Cvefeed, Gbhackers, Sans https://cvefeed.io/vuln/detail/CVE-2026-2545 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats
Post summary
The article reports several new CVEs with detailed technical descriptions, but does not provide proof‑of‑concepts, exploitation code, or evidence of active attacks.

