
Chess Electrics
Strong
Electrical Contractor
Strong
Electrical Contractor
Strong
Northam Platinum Holdings Limited (Northam Holdings or the group) is an independent, empowered, integrated producer of Platinum Group Metals (PGMs) that operates three wholly-owned mines located in the Bushveld Complex of South Africa, Zondereinde, Booysendal and Eland. Northam Platinum Limited (Northam) has been listed on the Johannesburg Stock Exchange (JSE) since 1987 with the share code NHM. This has been subsequently replaced with NPH following the listing of Northam Holdings in a share for share exchange. Our three main products mined are platinum, palladium and rhodium and are consumed by industries such as motor manufacturing, jewellery and other industrial sectors. Our activities are integrated throughout the full value stream, from underground mining, through concentrating, smelting and base metal removal to final saleable metal. Precious metal refining is outsourced. Since inception, Northamโs precious metals were refined by Heraeus Deutschland GmbH & Co KG (Heraeus) in Germany, however with the increase in our production base and refining capacity, the group has recently contracted Johnson Matthey PLC as a second precious metal refiner. The growth of our business ensures meaningful employment for our people. We create opportunities for training and skills development both for employees and the communities where we operate. At Northam, we believe in the positive impact of mining not only for our investors but for our communities, our environment and our people.
Security & Compliance Standards Overview
No incidents recorded for Chess Electrics in 2025.
No incidents recorded for Northam Platinum in 2025.
Chess Electrics cyber incidents detection timeline including parent company and subsidiaries
Northam Platinum cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
Improper Protection Against Voltage and Clock Glitches in FPGA devices, could allow an attacker with physical access to undervolt the platform resulting in a loss of confidentiality.
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the question object, regardless of whether the user has unlocked them via point deduction. Users can view all hints for free, undermining the business logic of the platform and reducing the integrity of the challenge system. This issue has been patched in version 2.3.0.
Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high-privilege badges (e.g., Staff) to themselves. This could lead to privilege escalation and impersonation of administrative roles. This issue has been patched in version 2.2.0.
parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState function of parse version 5.3.0 and before allows attackers to inject properties on Object.prototype via supplying a crafted payload, causing denial of service (DoS) as the minimum consequence.