Urgent.News

What's breaking now, across thousands of outlets.

Tech

Web attacks up 44pc as hackers target State, ISP systems

Government systems and ISPs emerge as prime targets for attackers.

Web attacks up 44pc as hackers target State, ISP systems

Kenya has witnessed a significant 44% rise in web application attacks, posing serious threats to data theft, unauthorized access, and system compromise for both businesses and public agencies. During the three months ending June, Kenya recorded a 43.7% increase in web application attacks, with authorities issuing 10.6 million advisories, marking only a minor 1.9% increase from the previous quarter.

Web application attacks involve malicious activities aimed at stealing data, compromising servers or disrupting operations. The vulnerabilities often arise when developers make errors that permit unauthorized access to sensitive data or administrative privileges. Most targets were government systems and Internet Service Providers (ISPs), with attackers focusing on user authentication credentials, vulnerable web browsers, and database servers containing sensitive information.

Most attacks exploited weaknesses in SSL/TLS security configurations, enabling unauthorized access and intercepting sensitive data during transmission.

As businesses and public agencies increasingly digitize services, the number of accessible applications, databases, and interfaces has expanded, creating more targets for cybercriminals. Kenya's digital economy, including financial services, commerce, government services, and cloud infrastructure, has grown significantly, drawing more attackers seeking valuable rewards.

According to the Communications Authority of Kenya (CA), many cyber threats stem from inadequate system patching, weak user awareness, and the malicious use of artificial intelligence. However, the CA highlights software architecture weaknesses, third-party components, and security configurations as the primary routes exploited by attackers.

The CA advises organizations to disable SSL 3.0 support, replace end-of-life products, and promptly apply security patches and updates to mitigate risks. Despite these challenges, organizations must address legacy systems alongside newer applications, given the high costs and disruptions associated with replacing outdated infrastructure.

Written by urgent.news from Nation Africa's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at nation.africa →

More in Tech

More from Thursday 3 September →