⭕️ آسیب پذیری Unauthenticated File Upload RCE یک آسیبپذیری بحرانی در کامپوننت RSFiles! (com_rsfiles) برای Joomla با شناسه CVE-2026-57827 منتشر شده است. این نقص از نوع Unauthenticated File Upload بوده و به مهاجم اجازه میدهد بدون نیاز به احراز هویت , فایل دلخواه خود را روی سرور آپلود کند. ریشه آسیبپذیری، Split-Controller Upload Bypass است که منجر به دور زدن کنترلهای امنیتی فرآیند آپلود شده و در نهایت امکان نوشتن…

Channel
Meshkatnet
@meshkatnet
On this record: Topic · Growth · Engagement · Reactions · Advertising · Posts · Telegram's recommendations · Cite this entry
644subscribers
+4 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of Under 1,000.
Register entry
| Telegram ID | -1001003835549 |
|---|---|
| Type | Channel |
| Username | @meshkatnet |
| Created | Between 1 September 2015 and 31 December 2015 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 7 August 2026 |
| Last confirmed live | 14 September 2026 |
| Measurements held | 6 |
| Confirmed unchanged | 2 times, most recently 14 September 2026 |
| On Telegram | t.me/meshkatnet |
Topic
Hacking & security — a classification, not a measurement. An on-box language model (Qwen3.6-35B-A3B-FP8, prompt version 1) read this channel’s own recent posts on 20 September 2026 and assigned it the closest of 31 fixed categories, at 100% confidence. This is a model’s judgement about what the channel is likely to be about, not a fact this register measured the way a subscriber count or a view count is measured — it can be revised on a later pass, and it carries no weight anywhere else on this page. How this classification works, and why it has no browse page of its own yet.
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 6 Sept 2026, 17:20 | 644 | +1 |
| 28 Aug 2026, 08:11 | 643 | +1 |
| 21 Aug 2026, 05:38 | 642 | +1 |
| 14 Aug 2026, 21:28 | 641 | +1 |
| 7 Aug 2026, 08:48 | 640 | no change |
| 7 Aug 2026, 08:24 | 640 | first reading |
Engagement
20 posts held, back to 30 March 2025 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 page of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 31 July 2026. An engagement rate over an empty window would be a number about nothing.
Reaction mix
10 reactions across 6 posts, in 3 distinct kinds. The most used accounts for 50.0% of them.
| Reaction | Count | Share | Share, drawn |
|---|---|---|---|
| 👍 | 5 | 50.0% | |
| ❤ | 4 | 40.0% | |
| 🙏 | 1 | 10.0% |
No sentiment is inferred, and none should be read in. This table is ordered by count and by nothing else. Emoji do not carry stable meaning across languages or communities — 🙏 is thanks in one channel and mourning in another — so we publish which ones were pressed and how often, and pass no judgement on what an audience meant by them.
Precision. Telegram publishes reaction counts per emoji and short-forms each one — 4.34K, 1.2M — so any single kind at or above 1,000 reaches us at three significant figures, and only counts below 1,000 are exact. The shares above are ratios of those figures and carry the same error. This is also why the total here can differ slightly from a reaction total printed elsewhere on the page: both are sums of the same rounded parts, taken over samples with different edges.
Coverage. Reactions were read on 6 of the 20 sampled posts in this sample. Summed by Telegram’s own count on each post — not by adding up the per-emoji breakdown above — those same posts carry 10 reactions in total: the kind of figure the paragraph above means by “a reaction total printed elsewhere on the page”.
Measured over the 20 most recent posts we hold, published 30 March 2025 to 31 July 2026, using the newest reading held for each. Telegram Stars are excluded: they are a payment, not a reaction, and they have their own section.
Advertising
- Ad load
- 5.00%
- 1 of 20 posts carry an ad marker
- Regulatory tokens
- 0
- none — marked by hashtag only
- Median views · ads
- 257
- over 1 measured post
- Median views · rest
- 289
- over 19 measured posts
An ad marker, not a judgement about a post. A post is counted here because it carries one of two explicit markings: an erid token, which Russian law has required on paid placements since 2022 and which is issued against a specific advertising contract, or a #реклама / #ad hashtag in the body, which is the channel declaring it itself. The first is documentary; the second is a self-declaration and is weaker. No classifier reads the text and decides — nothing on this site guesses that a post is an advertisement.
This is a floor, and it can only ever be a floor. A channel that runs paid placements without marking them produces no marker for us to count, and an unmarked ad is indistinguishable from an ordinary post on the public surface. The ad load above therefore means “the share of posts that declared themselves”, never “the share of posts that were paid for”. A low figure is not evidence of a channel that runs few ads.
Both figures are medians, and no ratio between them is published. Each is a view reading that actually occurred on a post, picked by percentile_disc rather than averaged, so one viral post cannot move it and no interpolated value is invented between two readings. The sample on one side is under five posts, which is too thin to compare. The two figures are shown side by side with the count behind each, and deliberately not divided into a headline like “ads get x% fewer views” — an arithmetic that is easy to print and, at this sample size, means nothing.
Measured over the 20 most recent posts we hold, published 30 March 2025 to 31 July 2026. Views are the latest single reading held for each post, and any reading at or above 1,000 is rounded by Telegram to three significant figures.
Recent posts
⭕️ هشدار | بهرهبرداری فعال از آسیبپذیری 0day در Cisco FMC مهاجمان در حال سوءاستفاده از آسیبپذیری Zero-Day با شناسه CVE-2026-20316 در Cisco Firepower Management Center (FMC) هستند. این آسیبپذیری به مهاجمان از راه دور و بدون نیاز به احراز هویت اجازه میدهد با استفاده از اعتبارنامههای ثابت (Static Credentials) به یک حساب کاربری با سطح دسترسی پایین وارد شده و به اطلاعات حساس سیستم دسترسی پیدا کنند. شرکت Cisco هشد…
⭕️ آسیبپذیری جدید و پرخطر در 7-Zip امکان اجرای کد مخرب را فراهم میکند. یک آسیبپذیری تازه با شناسه CVE-2026-14266 در نرمافزار 7-Zip افشا شده است که میتواند به هکرها اجازه دهد با فریب کاربر برای باز کردن یک فایل XZ دستکاریشده، کد دلخواه خود را روی سیستم اجرا کنند. این نقص امنیتی از نوع Heap Overflow در ماژول پردازش فایلهای XZ است و شدت آن بالا (High Severity) ارزیابی شده است. در صورت موفقیت حمله، کد مخرب با همان…
⭕️ در جریان یک پروژه تحقیقاتی روی آسیبپذیریهای 0day در SharePoint، تیم Rapid7 Labs دو آسیبپذیری جدید را کشف کرد که با chain آنها میتوان روی یک سرور آسیبپذیر، RCE به دست آورد. امروز Rapid7 و Microsoft نخستین آسیبپذیری این زنجیره را با شناسه CVE-2026-55040 منتشر کردند. این نقص، امکان دور زدن احراز هویت مبتنی بر توکن JWT در Microsoft SharePoint را فراهم میکند. https://www.rapid7.com/blog/post/ve-cve-2026-55040-…
⭕️ CVE-2026-47291 یک باگ بحرانی در درایور HTTP.sys ویندوز است که به مهاجم اجازه اجرای کد از راه دور در سطح کرنل را میدهد. مشکل اصلی در تابع UlpParseHeader() است: وقتی سرور هدرهای HTTP زیادی (حدود ۶۵ هزار خط) را در قالب پکتهای TLS جداگانه دریافت میکند، یک متغیر ۱۶-بیتی که اندازه بافر را مدیریت میکند سرریز (overflow) شده و به اعداد کوچک برمیگردد. نتیجه این است که درایور حافظه کمتری از آنچه نیاز است اختصاص میدهد …
⭕️ آسیبپذیری Onelogon که توسط تیم RUB-SoftSec در مقاله USENIX WOOT’26 مستند شده، یک نقص امنیتی ناشی از پیادهسازی ناقص پچ Zerologon است؛ مایکروسافت برای حفظ سازگاری با سیستمهای قدیمی، سازوکار استثنای VulnerableChannelAllowList را در پروتکل Netlogon اضافه کرد که همین لیست به مهاجم اجازه میدهد با حمله Meet-in-the-Middle و بدون نیاز به credential معتبر، کنترل کامل Domain Controller و کل دامنه را به دست آورد. برخلاف …
🎥 فکر میکنی مانیتورت واقعاً روی 60Hz یا 120Hz کار میکنه؟ 🌀 خیلی از کاربرا بعد از خرید مانیتورهای 120Hz، 144Hz یا حتی 165Hz متوجه میشن که ویندوز هنوز روی 60Hz تنظیم شده و از تمام توان نمایشگر استفاده نمیکنن! 🌐 سایت TestUFO بهت نشون میده نرخ نوسازی واقعی نمایشگرت چقدره، فریمدراپ داری یا نه، Motion Blur چطوره و آیا تنظیمات نمایشگر درست انجام شده یا نه. 🔗 testufo.com ✅ اگه عدد نمایش داده شده با مشخصات مانیتورت یک…
یک ایده ساده برای سیم ها در شبکه با این روش می توانید سیم ها و کابل های نامنظم را به صورت زیبا و منظم در کنار یکدیگر آرایش دهید و از کار خود لذت ببرید . 🆔 @meshkatnet ✉️ [email protected] 🌍 www.meshkatnet.ir 🆔 @meshkatnet
👍2
⭕️ اکستنشن APIReaper برای سادهتر کردن تست API داخل Burp Suite طراحی شده است. با این ابزار میتونید Swagger یا Postman Collection رو لود کنید، endpointها رو بهصورت دستهبندیشده ببینید و بدون نیاز به وارد کردن دستی، درخواستها رو مستقیم به Repeater بفرستید. همچنین امکان تنظیم Base URL و Authorization توکنهای مختلف هم بهصورت یکجا روی همه درخواستها وجود داره. مناسب برای Pentester و Bug Hunter ها. لینک پروژه: https:…
⭕️ در تحلیل آسیبپذیری بحرانی CVE-2026-20182 در پشته شبکه Cisco Catalyst SD-WAN، یک نقص منطقی (Logic Bug) قابل توجه در تابع vbond_proc_challenge_ack شناسایی شد . این حفره امنیتی در لایه DTLS (پورت ۱۲۳۶) و سرویس vdaemon واقع شده است؛ جایی که برخلاف سایر تجهیزات مانند vSmart یا vEdge، برای دستگاههای نوع ۲ یعنی vHub، هیچ مکانیزم راستیآزمایی (Verification) تعریف نشده است. به محض دریافت پیام CHALLENGE_ACK با هویت جعلی،…
❤2
Security Update – Microsoft October 2025 Patch Tuesday Vulnerabilities: Multiple Critical and Zero-Day Vulnerabilities Across Microsoft Products CVEs: CVE-2025-0033 – AMD Restricted Memory Page Corruption (Zero-Day / Critical) CVE-2025-24052 – Agere Modem Driver Elevation of Privilege (Zero-Day) CVE-2025-24990 – Agere Modem Driver Elevation of Privilege (Zero-Day) CVE-2025-2884 – TPM 2.0 Out-of-Bounds Read (Zero-Day)…
Security Update – Cisco Secure Firewall ASA & FTD VPN Web Server Vulnerability: Remote Code Execution – VPN Web Server Input Validation Flaw CVE: CVE-2025-20333 Severity: 9.9 (Critical) Summary: A critical remote code execution (RCE) vulnerability exists in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software. The issue stems fr…
Showing the 12 most recent of 20 posts we hold for @meshkatnet. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Appears in Telegram’s recommendations for other channels
The reverse of the list above, and a different kind of signal. This does not require this channel to have ever been asked about directly — each row below is a channel we DID ask Telegram about, whose Telegram-generated list happened to include this one. A channel can appear here with an empty list above it, because being named by someone else’s query is independent of having been queried itself.
@whesfahan · 26,011
Telegram ranks this channel #19 of 65 here — alongside 64 others — read 21 September 2026
@ielts_990 · 45,351
Telegram ranks this channel #52 of 70 here — alongside 69 others — read 27 August 2026
@eestekhdam_esfahan · 35,063
Telegram ranks this channel #68 of 77 here — alongside 76 others — read 3 September 2026
This channel appears in 3 seed channels' Telegram-generated recommendation lists in total. Each is Telegram’s list for THAT channel, not this one — see how this is measured.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 6 September 2026 — this entry's latest reading, not the date you are reading this.
“Meshkatnet” (@meshkatnet), 644 subscribers as measured 6 September 2026. Telegram Register, tgregister.com/channel/meshkatnet.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.