Kenyan government systems and Internet Service Providers (ISPs) are facing a growing cyber threat after attacks targeting web applications rose by 43.7 percent in the three months to June, raising concern over the safety of sensitive data and online services.
The sharp increase came as more public agencies and businesses shifted services and transactions to digital platforms, creating a wider pool of websites, databases and online systems that can be targeted by criminals.
The Communications Authority of Kenya (CA) said government systems and ISPs were the main targets during the period, with attackers focusing on obtaining user login details, exploiting weak web browsers and gaining access to database servers holding sensitive information.
"Government systems and Internet Service Providers (ISPs) constituted the primary targets, with threat actors prioritising the compromise of user authentication credentials, vulnerable web browsers and database servers," said the CA.
The regulator said some of the attacks took advantage of weaknesses in SSL/TLS security settings, which can leave systems open to unauthorised access and allow sensitive information to be intercepted while being transmitted.
"A significant proportion of attacks exploited weaknesses in SSL/TLS security configurations, enabling unauthorised access to systems and the interception of sensitive data during transmission."
The attacks were not limited to attempts to bring websites down. Once criminals gain entry through weaknesses in web applications, they can move further into an organisation's systems, access databases, obtain higher levels of access and expose information that should remain protected.
The CA also identified several weaknesses that attackers were using to break into systems. These included unauthenticated remote-code execution, privilege escalation and reflected cross-site scripting, all of which can provide a path to systems and sensitive information.
Web application attacks involve malicious attempts to target websites and online portals with the aim of stealing information, gaining access to systems or interfering with their operations.
The risk increases where developers make mistakes that leave applications poorly protected. Such gaps can allow people without permission to reach sensitive data or gain administrative rights.
The latest rise comes against the backdrop of Kenya's expanding digital economy, with financial services, businesses, government services and cloud-based systems increasingly relying on online platforms.
As more services move online, organisations are also being exposed to a larger number of applications, databases and other systems that can be reached through the internet.
The CA said the situation places greater pressure on organisations to keep checking and securing their applications even after they have been deployed. This is especially important for websites and online systems that depend on software developed by outside providers, libraries and other third-party services.
Despite the sharp rise in web application attacks, the wider number of cyber threat events recorded in the country fell during the period.
Kenya recorded 2.36 billion cyber threat events between April and June, representing a 30.03 percent drop from the previous quarter.
System attacks remained the biggest category, accounting for 2.25 billion attempts during the three months. They were followed by malware attacks at 59 million and brute-force attacks at 24.2 million.
The CA linked many of the wider cyber threats to poor system patching, limited awareness among users and the malicious use of artificial intelligence (AI), which can help criminals carry out more advanced attacks.
For web applications, however, the regulator pointed to weaknesses in software design, third-party components and security settings as key entry points being used by attackers.
The authority has advised organisations to take steps to close some of these gaps, including disabling support for SSL 3.0, replacing products that have reached the end of their useful life and installing security patches and updates as soon as they become available.
The recommendations also point to the challenge facing organisations that continue to operate old systems while introducing newer digital platforms. Replacing outdated infrastructure can be expensive or cause disruption, leaving some organisations having to secure older technology alongside new applications.
With government agencies, businesses and other organisations continuing to move services online, the rise in attacks shows the growing need to keep web applications and the systems behind them secure after they are put into use.