Malawi CERT

NATIONAL ICT INNOVATION AWARDS 2026

The Malawi Communications Regulatory Authority (MACRA) is turning up the volume on local innovation!  We are thrilled to celebrate 20 groundbreaking innovators who are reshaping Malawi’s digital landscape with homegrown solutions in agriculture, health, and finance. These tech pioneers have been shortlisted to showcase their innovative projects at the inaugural National ICT Innovation Awards. Join us in celebrating […]

NATIONAL ICT INNOVATION AWARDS 2026 Read More »

MACRA COMMEMORATES SAFER INTERNET DAY

Bungwe la MACRA mothandizana ndi a Youth Net Counselling (YONECO) alangiza zakufunikira kogwirana manja poonetsetsa kuti ana ali otetezeka pamene akugwiritsa ntchito intaneti. Izi zinakambidwa pa sukulu ya Zomba Catholic Secondary pamwambo okumbukira malo otetezeka pa intaneti padziko lonse, womwe umakumbukiridwa pa 2 February chaka chilichonse, ndipo dziko la Malawi likuchita mwambowu kuyambira pa 23

MACRA COMMEMORATES SAFER INTERNET DAY Read More »

MACRA Trains Police PRO’s and Prosecutors on Cybersecurity and Data Protection

MACRA has trained Malawi Police Service Public Relations Officers and Prosecutors in its capacity as the designated Data Protection Authority and the national focal point for cybersecurity in Malawi. The training aimed to equip Public Relations Officers and Prosecutors with knowledge on data protection as well as cybersecurity. Inspector General of Police, Richard Luhanga, called

MACRA Trains Police PRO’s and Prosecutors on Cybersecurity and Data Protection Read More »

MACRA Successfully Commemorates Data Privacy Week

The Malawi Communications Regulatory Authority (MACRA), in its role as the designated Data Protection Authority, has successfully concluded this year’s Data Privacy Week, marked by public awareness activities, stakeholder engagement, and a national conference aimed at promoting responsible handling of personal data in Malawi. The week commenced with a Big Walk in Lilongwe, officially opened

MACRA Successfully Commemorates Data Privacy Week Read More »

Malawi CERT Hosts a COP Trainer of Trainers Workshop for Teachers in the South West Division

Chief Economist in the Ministry of Gender, Children, Disability and Social Welfare, Peter Mwale, has called for urgent and effective measures to protect children from cyberbullying and online exploitation. He was speaking in Liwonde during the “Training of Trainers” workshop for teachers in the South-East Education Division organized by MACRA’s Malawi Computer Emergency Response Team

Malawi CERT Hosts a COP Trainer of Trainers Workshop for Teachers in the South West Division Read More »

Critical RCE Vulnerability in Legacy D-Link DSL Routers Under Active Exploitation

Background A critical security vulnerability has been identified in legacy D-Link DSL gateway routers, tracked as CVE-2026-0625 with a CVSS score of 9.3. The vulnerability stems from improper sanitization of user-supplied input in the dnscfg.cgi endpoint, enabling unauthenticated command injection and remote code execution. Active exploitation of this flaw has been observed in the wild,

Critical RCE Vulnerability in Legacy D-Link DSL Routers Under Active Exploitation Read More »

Malawi CERT Hosts a COP Trainer of Trainers Workshop for teachers in the Northern Region

We have successfully wrapped up our cyber drills and awareness campaign at the University of Livingstonia in Rumphi. The event was a huge success, with students and staff gaining new knowledge on cyber security and data protection. Addressing the university community, Head of Malawi Computer Emergency Response Team (MwCERT), Christopher Banda emphasized the need for

Malawi CERT Hosts a COP Trainer of Trainers Workshop for teachers in the Northern Region Read More »

Malawi CERT Hosts a Cyberdrill at University of Livingstonia

We have successfully wrapped up our cyber drills and awareness campaign at the University of Livingstonia in Rumphi. The event was a huge success, with students and staff gaining new knowledge on cyber security and data protection. Addressing the university community, Head of Malawi Computer Emergency Response Team (MwCERT), Christopher Banda emphasized the need for

Malawi CERT Hosts a Cyberdrill at University of Livingstonia Read More »

Malawi CERT Hosts a Cyberdrill at Mzuzu University

MACRA through Malawi Computer Emergency Response Team (MwCERT) is carrying out cyberdrills targeting northern region tertiary institutions. On Wednesday, Mzuzu University ICT students were empowered with knowledge on cyber security. Christopher Banda, Head of CERT, briefed the students on various cyber-related topics, delving deeper into the cyber world. He emphasized the importance of cyber security

Malawi CERT Hosts a Cyberdrill at Mzuzu University Read More »

The Data Protection Authority Hosts an Awareness Workshop For the Tourism Sector

In today’s digital world, data is one of the most valuable assets and protecting it is more important than ever. Tourism professionals from across Malawi gathered for a Workshop on Data Protection for the Tourism Sector in Blantyre, a vital step toward building a safer, more trustworthy digital environment for travelers, operators, and stakeholders alike.

The Data Protection Authority Hosts an Awareness Workshop For the Tourism Sector Read More »

The Data Protection Authority Hosts an Awareness Workshop For the Financial Sector

MACRA through its Data Protection Authority (DPA), has intensified efforts to safeguard sensitive personal data within the financial sector. Speaking in Blantyre during a Data Protection workshop for Malawi’s Financial Sector, Head of Data Protection, Daniel Chiwoni, said the Authority is conducting targeted trainings on the newly enacted Data Protection Act to help institutions understand

The Data Protection Authority Hosts an Awareness Workshop For the Financial Sector Read More »

Malawi CERT Hosts a Cyberdrill at the Malawi University of Business and Applied Sciences

The Malawi Computer Emergency Response Team (mwCERT) hosted a cyber drill for the Malawi University of Business and Applied Sciences (MUBAS).The drill forms part of mwCERT’s efforts to raise awareness on cybersecurity and provide a platform to strengthen students’ capacity in the field. Speaking during the event, Dr Patrick Chikumba, Head of Computer Science and

Malawi CERT Hosts a Cyberdrill at the Malawi University of Business and Applied Sciences Read More »

Malawi CERT Hosts a COP Trainer of Trainers Workshop for teachers in the South West and Shire Highlands Education Divisions

MACRA, through MwCERT, has hosted a Child Online Protection trainer-of-trainers workshop in Blantyre targeting teachers from South West and Shire Highlands Education Divisions. Christopher Banda, Head of CERT, noted teachers’ crucial role in protecting children online. He observed that today’s youth are highly familiar with online platforms, making them vulnerable to cyberbullying and online crimes.

Malawi CERT Hosts a COP Trainer of Trainers Workshop for teachers in the South West and Shire Highlands Education Divisions Read More »

Malawi CERT Hosts a Cyberdrill at the Malawi University of Science and Technology

The Malawi Computer Emergency Response Team (Malawi CERT) successfully held a two-day cybersecurity capacity-building event at the Malawi University of Science and Technology (MUST) from the 11th to the 12th of August 2025. Organized in collaboration with MUST and the Malawi Research and Education Network (MAREN), the event aligned with Malawi CERT’s mandate to coordinate

Malawi CERT Hosts a Cyberdrill at the Malawi University of Science and Technology Read More »

MWCERT Hosts a Capture The Flag Challenge At the Women and Girls In cyber Conference

As part of the third edition of the Women and girls in cyber conference MwCERT hosted a Capture the flag competition (CTF). A CTF is a cybersecurity competition where participants solve challenges to find “flags,” which are pieces of information or code. The challenge was organized to empower and equip the young girls with technical

MWCERT Hosts a Capture The Flag Challenge At the Women and Girls In cyber Conference Read More »

MWCERT Hosts 22 Signals Brigade Students

MACRA’s Malawi Computer Emergency Response Team (mwCERT)  hosted a cybersecurity awareness lecture for Malawi Defence Force’s Upgrading Signals students from the 22 Signals Brigade. The session in Lilongwe aimed to enhance national understanding of digital safety and legal protections under the Malawi Communications Act (2016). It highlighted key cybersecurity issues, focusing on how to respond

MWCERT Hosts 22 Signals Brigade Students Read More »

MWCERT Hosts MDF Command And Staff College Students

  MACRA’s Malawi Computer Emergency Response Team (mwCERT) had the pleasure to host an educational tour for students from Malawi Defence Force Command and Staff College students in Lilongwe to strengthen awareness and preparedness in addressing emerging security threats.. Held under the theme “Confronting the Unknown: Strategies to Counter Emerging Transnational Security Threats”, the tour

MWCERT Hosts MDF Command And Staff College Students Read More »

MWCERT Takes Part In The Africa Regional Cyberdrill

  The Malawi Computer Emergency Response Team (mwCERT) has enhanced its cyber security skills through the thirteenth edition of the regional Cyberdrill for Africa Region taking place in Brazzaville, Republic of Congo. The four-day drill organised by International Telecommunication Union (ITU) and Interpol aimed at strengthening cyber security readiness in the African region.  The meeting 

MWCERT Takes Part In The Africa Regional Cyberdrill Read More »

MWCERT Takes Part In The National Youth Summit 2025

MACRA mentored over 600 youth leaders through a partnership with the National Youth Council of Malawi (NYCOM) at the ongoing 2025 National Youth Summit in Lilongwe. The summit, which drew participants from Malawi’s 28 districts and international delegates, provided a platform to empower young people with digital skills, innovation opportunities, and leadership mentorship. An Incident

MWCERT Takes Part In The National Youth Summit 2025 Read More »

Data Protection Authority Engages Government Institutions In a Data Protection Awareness Drive

MACRA through the Data Protection Authority (DPA) has engaged Government Institutions in a Data Protection Awareness drive to enhance data privacy and security in Malawi’s public sector. During the meeting in Lilongwe, MACRA Board Director Mr Isaac Songea, stressed the importance of safeguarding personal data in today’s digital era: “Personal data is one of the

Data Protection Authority Engages Government Institutions In a Data Protection Awareness Drive Read More »

SonicWall reveals two security flaws impacting its SMA100 Secure Appliances

EXPLOIT This flaws were being exploited by use of the following CVEs CVE-2023-44221 (CVSS score: 7.2) – Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a ‘nobody’ user, potentially leading to OS Command Injection Vulnerability CVE-2024-38475 (CVSS score: 9.8)

SonicWall reveals two security flaws impacting its SMA100 Secure Appliances Read More »

MACRA hosts a Validation Workshop on the Data Protection Regulations

MACRA hosted a Validation Workshop on the Data Protection Regulations and proposed registration fees for Data Controllers and Data Processors of Significant Importance at the Bingu International Convention Centre (BICC). This important workshop is platform where we are discussing stakeholder comments on the draft regulations as read with the Authority’s determination which has informed the

MACRA hosts a Validation Workshop on the Data Protection Regulations Read More »

Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach

BACKGROUND Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no evidence of unauthorized data access. RECOMMENDATION To mitigate the risk posed by such attacks, clients are advised to apply a Conditional Access policy to all Microsoft 365, Dynamics

Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach Read More »

Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers

BACKGROUND Researchers have shed light on a new campaign targeting WordPress sites that disguises the malware as a security plugin. The plugin, which goes by the name “WP-antymalwary-bot.php,” comes with a variety of features to maintain access, hide itself from the admin dashboard, and execute remote code. “Pinging functionality that can report back to a

Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers Read More »

WooCommerce admins targeted by fake security patches that hijack sites

BACKGROUND Once installed and activated, it provides threat actors administrator access to the dashboard and makes use of the REST API to facilitate remote code execution by injecting malicious PHP code into the site theme’s header file or clearing the caches of popular caching plugins. A new iteration of the malware includes notable changes to

WooCommerce admins targeted by fake security patches that hijack sites Read More »

MACRA Holds a two-day workshop aimed at developing Malawi’s National Position on the Interpretation of International Law and the State Use of ICT

Malawi has took a significant step towards shaping its digital future by holding an ICT indaba aimed at developing the country’s National Position on how International Law applies to the use of ICTs by states. The ICT indaba, took place in Lilongwe, has been organised by MACRA in partnership with the United Nations Institute for

MACRA Holds a two-day workshop aimed at developing Malawi’s National Position on the Interpretation of International Law and the State Use of ICT Read More »

MACRA hosts a Digital Rights workshop In Lilongwe

The Malawi Communications Regulatory Authority (MACRA) has called on Civil Society Organizations (CSOs) to enhance public awareness of digital laws and data protection, emphasizing their implications for individual rights. Speaking at a Digital Rights workshop in Lilongwe on Wednesday, Presidential Advisor on Non-State Actors, Martha Kwataine, who was the Guest of Honour, acknowledged MACRA for

MACRA hosts a Digital Rights workshop In Lilongwe Read More »

Finance and Telecommunications Sector Cybersecurity Conference

DAY 1 MACRA Board Director Reverend Father Damaseke has described the Cyber Security Conference for the Banking and Telecommunications sector as pivotal in the digital agenda drive, especially in its drive towards a more secure and resilient cyberspace for all. Father Damaseke was speaking when he officially opened the conference taking place in Mangochi under

Finance and Telecommunications Sector Cybersecurity Conference Read More »

Malawi CERT Conducts A Training For Upcoming Sectoral CERTs

 The Malawi Computer Emergency Team (Malawi CERT), in conjunction with the Forum for Incident Response and Security Team (FIRST), conducted a two day sectoral sector training at Nkopola, Mangochi. Under the theme ‘Navigating Cyber Security in Finance and Telecommunications’, the training aimed at equipping technical personel in these sectors with technical knowlenge in Incident response

Malawi CERT Conducts A Training For Upcoming Sectoral CERTs Read More »

FINANCE AND TELECOMMUNICATION SECTOR WORKSHOP

The Malawi Computer Emergency Response Team (CERT) has organized a comprehensive cybersecurity workshop targeting the Finance and Telecommunication sectors. The event is scheduled to take place from February 24-28, consisting of two primary components: Technical Training: A technical training session will be held on February 24-25, focused on preparing participants for upcoming sectoral CERTs in

FINANCE AND TELECOMMUNICATION SECTOR WORKSHOP Read More »

Government of Malawi officially launches the Child Online Protection Initiative

 On the 7th of February 2025 the Government of Malawi officially launched the Child Online Protection Initiative.The First Lady Madam Monica Chakwera who is the the Child Online Protection Ambassador called for a shared a responsibility in ensuring the protection and safety of children in the country on digital platforms. Presiding over the official launch

Government of Malawi officially launches the Child Online Protection Initiative Read More »

Macra officially closes the Cybersecurity Awareness Month

 The Authority officially closed the set-aside month of November as the cyber security awareness month under the theme “Secure Our World”.The closing event took place at Kamuzu Stadium in Blantyre with different activities to mark the day. MACRA Board Director Stella Chuthi is presiding over the event. In her remarks, Chuthi said over the past

Macra officially closes the Cybersecurity Awareness Month Read More »

Cisco’s Decade-Old ASA WebVPN Vulnerability being Exploited by Attacker

The Malawi Computer Emergency Response Team warns cisco customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA).The vulnerability, tracked as CVE-2014-2120 (CVSS score: 4.3), concerns a case of insufficient input validation in ASA’s WebVPN login page that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS)

Cisco’s Decade-Old ASA WebVPN Vulnerability being Exploited by Attacker Read More »

Empowering the Next Generation: Cybersecurity Awareness School Outreach Program

In today’s digital age, cybersecurity is more important than ever. As students spend an increasing amount of time online, they are more vulnerable to online threats such as phishing, identity theft, and cyberbullying. To address this growing concern, we are excited to announce that a team led by our Consumer Affairs Manager Mr Hatchson Mkwapatira

Empowering the Next Generation: Cybersecurity Awareness School Outreach Program Read More »

MACRA Visits Lilongwe Girls Secondary School in Commemoration of the Cybersecurity Awareness Month

The Authority set aside the month of November as the cyber security awareness month under the theme “Secure Our World”. As part of the commemoration one of the activities we are undertaking are school outreach programs. On the 15th of November the MACRA team  was at Lilongwe girls secondary school to educate and equip students on

MACRA Visits Lilongwe Girls Secondary School in Commemoration of the Cybersecurity Awareness Month Read More »

MACRA Visits Nyasa International Academy As Part of Cyber Security Awareness

.October is the Cyber Security Awareness Month. The month is being commemorated under the theme “Secure Our World”. Cybersecurity Awareness Month, aims to educate individuals and organizations about the importance of cybersecurity.. The concept revolves around promoting safe online practices, sharing knowledge about potential threats, and encouraging proactive measures to protect personal and sensitive information.

MACRA Visits Nyasa International Academy As Part of Cyber Security Awareness Read More »

Malawi rated highly in the 2024 Global Cybersecurity Index

The fifth edition of the Global Cybersecurity Index (GCI) 2024 has rated Malawi highly with a score of 80% from 36% in 2020. The report measures the commitment of countries to cybersecurity in the context of measures across the following five pillars: Legal, Technical, Organizational, Capacity development and Cooperation..  Reacting to the news, MACRA Director

Malawi rated highly in the 2024 Global Cybersecurity Index Read More »

Malware Locks Browser in Kiosk Mode to Steal Google Credentials

Malawi CERT advices google services users about a malware that is using the unusual method of locking users in their browser’s kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware. Specifically, the malware “locks” the user’s browser on Google’s login page with no obvious way to close

Malware Locks Browser in Kiosk Mode to Steal Google Credentials Read More »

New ‘Cuckoo’ Persistent macOS Spyware Targeting Intel and Arm Macs

Malawi CERT warns about a new information stealer targeting Apple macOS systems that’s designed to set up persistence on the infected hosts and act as a spyware. Hackers are using a new Mac malware to launch attacks against both newer Macs running Apple Silicon as well as older Intel-based Macs. Cuckoo, like the MacStealer macOS

New ‘Cuckoo’ Persistent macOS Spyware Targeting Intel and Arm Macs Read More »

Macra Hosts Digital Financial Service Security Workshop

The International Telecommunication Union (ITU) and #MACRA, through the Malawi Computer Emergency Response Team (mwCert), jointly organized a Digital Financial Services (DFS) Security Clinic. The Clinic, was held in Lilongwe and focused  on addressing security risks within the digital finance ecosystem,and it was  organized on the sidelines of an ITU regional workshop on Cost Models

Macra Hosts Digital Financial Service Security Workshop Read More »

MACRA unveils the First Lady Her Excellency Madam Monica Chakwera as Malawi’s Child Online Protection (COP) Ambassador

#MACRA has unveiled the First Lady Her Excellency Madam Monica Chakwera as Malawi’s Child Online Protection (COP) Ambassador.  Madam Chakwera was unveiled during a fundraising dinner held at Sanjika Palace in Blantyre for Shaping Our Future Foundation, a charity which she founded to promote holistic development and education of village girls and street children. Speaking

MACRA unveils the First Lady Her Excellency Madam Monica Chakwera as Malawi’s Child Online Protection (COP) Ambassador Read More »

Salima Secondary School

Unplanned early pregnancies among students has emerged as another negative impact of the internet. This was revealed at Salima Secondary School during the ongoing Safer Internet Day outreach campaign being held across the country. During the interface, the students admitted that they are addicted to watching pornographic materials with male friends and relatives, a development

Salima Secondary School Read More »

Chipoka Secondary School

Internet fraud particularly through social media has not spared the administration of examinations in secondary schools. In what could be termed as a groundbreaking revelation, one of the issues raised during the Safer Internet Day 2024 outreach program at Chipoka Secondary School was that some students fail examinations because they are deceived by fake examination

Chipoka Secondary School Read More »

Mchinji Secondary School

In Mchinji, it was another interesting and eye-opening encounter when the online safety outreach team visited Mchinji Secondary School. After the session, students pleaded for more open engagement and interface on cyber security, saying the exchange with the #MACRA outreach team has been an eye opener. The joint cyber safety awareness outreach were being held

Mchinji Secondary School Read More »

Ludzi Secondary School

Students from Ludzi Secondary School sent out a clarion call for a safer online space, arguing: “If we as young people suffer online violence, we cannot grow into productive citizens.” The Girls sent out the call during a cyber safety awareness outreach held at the school. The outreach was organized by #MACRA in partnership with

Ludzi Secondary School Read More »

Mzimba Secondary School, Nkhata-Bay Secondary School and in Rumphi, Bandawe Girls and Phwezi Girls and Boys Secondary schools.

Safer internet day (SID) is celebrated in the month of February and this year’s global theme is “Together for a better Internet”. This year the day was celebrated on Tuesday, February 7 and as a country, Malawi commemorated the day under the sub-theme “Inspiring Change? Making a difference, managing influence, and navigating change online”. MACRA

Mzimba Secondary School, Nkhata-Bay Secondary School and in Rumphi, Bandawe Girls and Phwezi Girls and Boys Secondary schools. Read More »

Chayamba Secondary school and Kamuzu Academy

Students from Chayamba Secondary school and Kamuzu Academy  have expressed gratitude for informative awareness sessions organised by #MACRA in partnership with local NGOs on the dangers and risks that go with digital communication services. The sentiments were made as the Safer Internet Day (SID) 2024 outreach campaign in the central region reached Kasungu district targeting

Chayamba Secondary school and Kamuzu Academy Read More »

Kaseye Girls Secondary School

#MACRA’s Safer Internet Day 2024 has not left any part of the country. The north also had a share of the outreach activities which were being conducted in several secondary schools across the region.In the north, the exercise was conducted in partnership with Youth-Watch Society and reached Kaseye Girls Secondary School in Chitipa. The outreach

Kaseye Girls Secondary School Read More »

Ntcheu Secondary School

As the national Safer Internet Day 2024 school outreach program continues, Malawi Communications Regulatory Authority (MACRA) was on Monday at Ntcheu Secondary School. During the interface with the students from the school, it was revealed that students are among the main target of mobile money fraudsters, with most of them reporting to have fallen victim

Ntcheu Secondary School Read More »

Kalibu Academy, Chichiri secondary school and Blantyre Secondary Schools.

The Malawi Communications Regulatory Authority (MACRA) held school outreach programs as part of the Safer Internet (SID) 2024 commemoration. The school outreach program is aimed at equipping school going children with digital literacy skills and good cyber hygiene practices as they navigate the digital spaces. The outreach team visited  Kalibu Academy, Chichiri secondary school and

Kalibu Academy, Chichiri secondary school and Blantyre Secondary Schools. Read More »

Beware of “I can’t believe he is gone” Facebook phishing posts

The Malawi Computer Emergency Response Team (Malawi CERT)warns about a widespread Facebook phishing campaign stating, “I can’t believe he is gone. I’m gonna miss him so much,” leads unsuspecting users to a website that steals your Facebook credentials. The Facebook phishing posts come in two forms, with one simply stating, “I can’t believe he is

Beware of “I can’t believe he is gone” Facebook phishing posts Read More »

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

The Malawi Computer Emergency Response Team (Malawi CERT)warns about pirated applications that are targeting Apple macOS users containing a backdoor capable of granting attackers remote control to infected machines.”These applications are being hosted on Chinese pirating websites in order to gain victims,” a Threat Labs researcher said. Once detonated, the malware will download and execute

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software Read More »

Macra conducts regional public relations workshop for the Malawi Police Service (MPS) Public Relation Officers (PRO)

The Authority conducted regional public relations workshop for the Malawi Police Service (MPS) Public Relation Officers (PRO) under the theme “Policing in the Digital Era”.Speaking at the opening ceremony which took place in Blantyre at Mt. Soche MACRA DG Daud Suleman emphasized the need for a safe digital space if the country is to utilize

Macra conducts regional public relations workshop for the Malawi Police Service (MPS) Public Relation Officers (PRO) Read More »

Scroll to Top
Skip to content