MS

Meera Shah

Cybersecurity and privacy reporter

Meera Shah covers cybersecurity, privacy regulation, identity systems, and the practical risk decisions facing companies and consumers.

CybersecurityPrivacyRisk management

Recent stories by Meera Shah

Nginx UI MCP vulnerability: why this exploited flaw matters now
SecurityRansomware and Breaches
A newly exploited flaw in Nginx UI shows how quickly AI-connected management features can turn into a live server risk when core protections are skipped.
Meera ShahApr 23, 20263 min read
Risk, resilience, and the systems companies rely on.Read story
The Cisco SD-WAN vulnerability on CISA's list needs attention now
SecurityRansomware and Breaches
A Cisco SD-WAN flaw that was only part of a broader February advisory has become more urgent after CISA flagged it as actively exploited, pushing network teams to revisit internet-facing management setups that may have looked low priority weeks ago.
Meera ShahApr 22, 20264 min read
Risk, resilience, and the systems companies rely on.Read story
The Apache ActiveMQ vulnerability on CISA's exploited list needs faster patching
SecurityRansomware and Breaches
CISA says attackers are already exploiting the Apache ActiveMQ vulnerability tracked as CVE-2026-34197, turning an old piece of enterprise middleware into another urgent reminder that forgotten infrastructure still creates outsized security risk.
Meera ShahApr 22, 20264 min read
Risk, resilience, and the systems companies rely on.Read story
Entra passkeys on Windows bring phishing-resistant sign-ins to unmanaged PCs
SecurityIdentity Security
Microsoft has moved Entra passkeys on Windows into public preview, giving organizations a way to use device-bound passkeys on personal and shared PCs without relying on passwords.
Meera ShahApr 21, 20263 min read
Risk, resilience, and the systems companies rely on.Read story
Microsoft says device-code phishing has become a faster identity threat
SecurityIdentity Security
Microsoft’s April 6, 2026 research says attackers are scaling device-code phishing with automation and AI-written lures, turning a niche OAuth trick into a more practical account-takeover path.
Meera ShahApr 20, 20263 min read
Risk, resilience, and the systems companies rely on.Read story
Microsoft’s April hotpatch turned a Windows update bug into an identity warning
SecurityIdentity Security
Microsoft April 2026 Windows updates show why hotpatching, BitLocker recovery, domain controller stability, and sign-in reliability now belong in identity risk planning.
Meera ShahApr 20, 202614 min read
Risk, resilience, and the systems companies rely on.Read story