A sharp rise in attacks targeting web applications is exposing Kenyan businesses and public agencies to growing threats of data theft, unauthorised access and system compromise.
Kenya recorded a 43.7 per cent increase in web application attacks in the three months ended June, highlighting the security risks accompanying the rapid migration of services and transactions online.
During the period, authorities also issued 10.6 million advisories on related attacks, representing a marginal 1.9 percent increase from those recorded in the preceding quarter ended March.
Web application attacks are malicious activities targeting websites and online portals to steal data, compromise servers or disrupt operations.
Such applications can become vulnerable when developers make errors that allow unauthorised users to access sensitive data or obtain administrative rights.
The attacks can therefore enable criminals to move beyond disrupting websites, potentially accessing databases, escalating privileges and compromising information held by organisations.
In its latest update on cyber threats, the Communications Authority of Kenya (CA) said government systems and Internet Service Providers (ISPs) were the main targets, with attackers seeking user authentication credentials, vulnerable web browsers and database servers containing sensitive information.
“Government systems and Internet Service Providers (ISPs) constituted the primary targets, with threat actors prioritising the compromise of user authentication credentials, vulnerable web browsers and database servers,” said the CA.
“A significant proportion of attacks exploited weaknesses in SSL/TLS security configurations, enabling unauthorised access to systems and the interception of sensitive data during transmission.”
The regulator also identified unauthenticated remote-code execution, privilege escalation and reflected cross-site scripting as vulnerabilities being exploited to gain access and expose sensitive information.
The surge comes as businesses and public agencies move more services online, expanding the number of applications, databases and interfaces accessible through the internet.
Kenya’s digital economy is also growing across financial services, commerce, government services and cloud infrastructure, increasing both the value of online systems and the potential rewards for attackers.
The increase highlights mounting pressure on organisations to strengthen application security after deployment, particularly where websites rely on external software libraries and third-party services.
Across the wider cyber landscape, Kenya recorded 2.36 billion cyber threat events between April and June, a 30.03 percent decline from the previous quarter.
System attacks remained the largest category, accounting for 2.25 billion attempts, followed by malware at 59 million and brute-force attacks at 24.2 million.
The CA attributed many cyber threats to inadequate system patching, weak user awareness and malicious use of artificial intelligence (AI) to conduct more sophisticated attacks.
For web applications, however, the report points more directly to weaknesses in software architecture, third-party components and security configurations as the main routes exploited by attackers.
The CA has advised affected organisations to disable SSL 3.0 support, replace end-of-life products and apply security patches and updates as soon as they are released.
The recommendations underscore a persistent challenge for organisations running legacy systems alongside newer applications, particularly where replacing outdated infrastructure is costly or disruptive.
Follow ourWhatsApp channel for breaking news updates and more stories like this.
