{
  "id": 5285413,
  "title": "Web attacks up 44pc as hackers target State, ISP systems",
  "url": "https://urgent.news/2026/09/03/web-attacks-up-44pc-as-hackers-target-state-isp-systems",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-03T03:00:00.000Z",
  "source": {
    "name": "Nation Africa",
    "slug": "nation-africa",
    "url": "https://nation.africa/kenya/business/web-attacks-up-44pc-as-hackers-target-state-isp-systems-5581506"
  },
  "original_language": "en",
  "account": "Kenya has witnessed a significant 44% rise in web application attacks, posing serious threats to data theft, unauthorized access, and system compromise for both businesses and public agencies. During the three months ending June, Kenya recorded a 43.7% increase in web application attacks, with authorities issuing 10.6 million advisories, marking only a minor 1.9% increase from the previous quarter.\n\nWeb application attacks involve malicious activities aimed at stealing data, compromising servers or disrupting operations. The vulnerabilities often arise when developers make errors that permit unauthorized access to sensitive data or administrative privileges. Most targets were government systems and Internet Service Providers (ISPs), with attackers focusing on user authentication credentials, vulnerable web browsers, and database servers containing sensitive information. Most attacks exploited weaknesses in SSL/TLS security configurations, enabling unauthorized access and intercepting sensitive data during transmission.\n\nAs businesses and public agencies increasingly digitize services, the number of accessible applications, databases, and interfaces has expanded, creating more targets for cybercriminals. Kenya's digital economy, including financial services, commerce, government services, and cloud infrastructure, has grown significantly, drawing more attackers seeking valuable rewards.\n\nAccording to the Communications Authority of Kenya (CA), many cyber threats stem from inadequate system patching, weak user awareness, and the malicious use of artificial intelligence. However, the CA highlights software architecture weaknesses, third-party components, and security configurations as the primary routes exploited by attackers.\n\nThe CA advises organizations to disable SSL 3.0 support, replace end-of-life products, and promptly apply security patches and updates to mitigate risks. Despite these challenges, organizations must address legacy systems alongside newer applications, given the high costs and disruptions associated with replacing outdated infrastructure.",
  "summary": "Government systems and ISPs emerge as prime targets for attackers.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}