The World Bank Group has imposed a minimum five-year debarment on Webmasters Kenya Limited and its founder and CEO, James Ayugi, citing fraudulent and obstructive practices during an international procurement process.The decision, contained in Sanctions Board Decision No. 147 (Sanctions Case No. 790), places renewed scrutiny on the Kenyan technology company, which has been associated with the development of eCitizen, Kenya’s central digital government services platform.According to findings published by the World Bank’s Integrity Vice Presidency (INT), the misconduct occurred during procurement processes for development projects in Somalia.Webmasters Kenya submitted bids to develop a Single Business Registration System for Somalia’s Ministry of Commerce and Industry under two World Bank-financed programmes: the Somali Core Economic Institutions and Opportunities Project (SCORE) and the Somalia Capacity Advancement, Livelihoods and Entrepreneurship through Digital Uplift Project (SCALED-UP).The World Bank found that Webmasters Kenya included the CVs of two proposed key experts in its technical bids, indicating that the professionals were committed to and available for the contracts.However, when the World Bank contacted the individuals, both denied authorising the use of their CVs or consenting to being listed as key experts.The Sanctions Board found that the misrepresentation was intended to improperly secure a financial benefit of $98,000, which had been allocated for expert remuneration.The World Bank also found that Webmasters Kenya obstructed a subsequent investigation.Following concerns raised during the procurement process, the bank issued an audit letter in November 2022 requesting accounting records, subcontractor agreements, invoices and corporate financial information.Despite receiving extensions and 10 written reminders, according to the findings, Webmasters Kenya did not provide the requested records. The company instead submitted broader project deliverables and high-level timelines.The Sanctions Board concluded that the company had materially impeded the World Bank’s inspection and audit rights.Responding to the debarment, Ayugi described the matter as an “administrative lapse” and a “compliance issue”, while presenting it as a learning experience for local technology companies.He also pointed to the company’s work in Somalia, saying the system it deployed had enabled local businesses to register in less than three days.The World Bank’s debarment, however, remains in effect for a minimum of five years, subject to the company’s fulfilment of specified conditions for release from sanction.The decision is likely to draw increased scrutiny to Webmasters Kenya’s public-sector contracts, particularly given the company’s association with eCitizen, a critical component of Kenya’s digital government infrastructure.Webmasters Kenya bills the national government between $773,000 and $1.55 million (KSh100 million to KSh200 million) every month to run and support the eCitizen gateway. The payments come amid concerns over systemic vulnerabilities within the platform, with a recent report by Kenya’s Auditor-General raising questions over its financial controls.The audit found that $2.7 million (KSh349 million) was overcharged to citizens through unapproved convenience fees, while $982,000 (KSh127 million) in government revenue was allegedly diverted from the official Paybill number 222222 to unverified private bank accounts.
Read briefing In 2019, I attended a government seminar and delivered a presentation with a Cheeky title, “Digitising public sector bureaucracy”. My central argument was simple, and at the time it unsettled a few people in the room: most technology projects, in most organisations, were not eliminating bureaucracy at all. They were digitising it. And government, more than almost any other sector I had seen, was remarkably effective at exactly that — taking a slow, paper-bound, multi-signature process and turning it into a slow, screen-bound, multi-click process. Same friction, same delay, same lack of accountability—just faster typing.I coined a term for it that day, somewhat off the cuff: “digitising the bureaucracy.” It landed harder than I expected. The Permanent Secretary presiding over the session picked it up and repeated it back to the room in his closing remarks, using it as shorthand for exactly the trap I was warning against.That moment has stayed with me, because the pattern I described in 2019 hasn’t gone away — it has simply migrated. It is no longer confined to government digitisation programmes. It is now the defining risk of enterprise AI transformation. There is a quiet assumption sitting underneath most transformation programmes today: that technology is the fix. Buy the platform, deploy the model, automate the workflow, and the organisation will somehow become more disciplined, more efficient, more “digital.” It rarely works that way. What actually happens, far more often than boards like to admit, is that badly governed processes get automated at speed — and the chaos that used to move at the pace of a human simply starts moving at the pace of a machine.Every transformation slide deck tells roughly the same story: legacy process on the left, sleek digital future-state on the right, an arrow labelled “AI” or “automation” pointing from one to the other. What the arrow conveniently skips over is the actual condition of the process being transformed. Is it well controlled? Is ownership clear? Does anyone actually know why the process works the way it does, or has it simply calcified into “the way we’ve always done it”?Organisations that skip this question don’t get transformation. They get a faster, better-branded version of their existing problems. A reconciliation process with unclear accountability doesn’t become accountable because it’s now run through an RPA bot. A lending decision shaped by inconsistent judgement doesn’t become consistent because a model now makes it — it becomes consistently opaque, and considerably harder to interrogate after the fact.This is the trap: technology projects are approved and funded as efficiency and growth initiatives, sitting under profit and transformation mandates, while the governance question — should we even be automating this, and is it safe to do so — gets treated as a downstream implementation detail rather than a precondition.Culture rarely appears on a transformation roadmap, and that omission is itself revealing. Culture is what determines whether risk gets raised or buried, whether a control failure is escalated or quietly worked around, whether “the system told me to” becomes an acceptable answer to an auditor. No amount of technology sophistication compensates for a culture where people don’t feel safe naming a problem.This matters more, not less, as organisations adopt AI. Automated systems don’t just execute a process — they encode an organisation’s tolerances. A culture that tolerates ambiguous ownership will produce an AI deployment with ambiguous ownership. A culture that treats controls as a compliance checkbox rather than a genuine safeguard will deploy AI the same way: as a checkbox exercise, rushed to production because a deadline is louder than a risk register.Technology inherits the culture of the organisation that builds it. If the culture is chaotic, the technology will digitise that chaos with impressive fidelity.There’s a persistent framing, especially in fast-moving technology functions, that controls and risk exist to slow things down — the department that says no while everyone else tries to ship. This framing is not just unhelpful, it inverts the actual value controls provide. A control is what allows an organisation to move quickly with confidence, because it defines the boundaries within which speed is safe.Controls that are designed after a system is already in production are not controls. They are documentation of what already happened, useful mainly for the post-incident review. Real control design has to happen before the technology decision is made — as part of the technology decision — not layered on afterward as a governance patch.This is precisely why AI Operations as a discipline matters: it is not simply “operations, but with AI in it.” It is the deliberate practice of building operating models where control design, risk appetite, and human accountability are established before the automation goes live, not reconstructed after something goes wrong. Enterprise AI transformation done properly is a controls-first exercise wearing a technology coat.
Read briefing Nairobi Proposes KES 5,000 Daily Fee for Professional Photo and Music Shoots Techweez
Read briefing Treasury Secretary Scott Bessent said countries doing business with Iran should sever those ties or face retaliation from the United States.Why it matters: A major sanctions and geopolitics story that could ripple through oil markets, trade routes and regional diplomacy.
Read briefing Comprehensive, up-to-date news coverage, aggregated from sources all over the world by Google News.
Read briefing Military officials from Uganda and Burundi reportedly held talks in Israel about joining a possible international security force for Gaza, adding an East African angle to Middle East diplomacy.Why it matters: This is geopolitically significant because it could draw African states into postwar Gaza security planning.
Read briefing Authorities have arrested four people and seized chemicals as investigations continue into the suspected poisoning of elephants in the Amboseli ecosystem, with the death toll rising to 18.Why it matters: The story links conservation, crime and tourism, and the investigation is still active with major ecological consequences.
Read briefing AP argues the world is moving toward more severe climate disruptions and that extreme events are becoming more likely and more damaging.Why it matters: Useful context package for newsroom planning, though more analytical than a straight lead.
Read briefing Copernicus data cited by AP shows global ocean temperatures reached a new record, underscoring strain on marine ecosystems and weather patterns.Why it matters: A consequential climate trend story that can anchor broader coverage on fisheries, food systems and extreme weather risk.
Read briefing The Kenya National Union of Nurses (KNUN) says it is ready to engage authorities in constructive dialogue to resolve the ongoing nationwide nurses’ strike.However, the union maintains that the industrial action, triggered by delayed promotions, unremitted statutory deductions and demands for permanent contracts for Universal Health Coverage (UHC) staff, will continue until key agreements are implemented.The nationwide strike, which began on July 29, 2026, centres on the non-implementation of Collective Bargaining Agreements (CBAs), delayed implementation of county-level return-to-work agreements and the permanent absorption of UHC staff.KNUN has vowed to continue with the strike, contending that the national and county governments have failed to implement the return-to-work formula agreed in 2017.KNUN Secretary-General Seth Panyako said the union remained committed to constructive dialogue and finding lasting solutions that safeguard the welfare of healthcare workers while strengthening healthcare service delivery across the country.Panyako spoke after holding a high-level consultative meeting with Mombasa Governor Abdulswamad Shariff Nassir, who is also the Chairperson of the Council of Governors (CoG) Committee on Health.He said nurses would not return to work until the government honours agreements reached with the union in 2017.Panyako said the strike was not about Mombasa County but was purely a national issue. He said Mombasa County had complied with the requirements by recruiting contract nurses to maintain normal hospital operations, while KNUN’s focus remained on addressing national concerns affecting nurses and midwives.“We have met Governor Nassir to deliberate and explore solutions to resolving the ongoing nationwide nurses’ strike,” he said.Panyako said the industrial action revolved around welfare and employment issues, maintaining that the dispute was with the employer and was not intended to harm patients.He described the meeting as a major step towards resolving the nationwide nurses’ and midwives’ strike, which has disrupted services in public health facilities.“We are committed to multi-level diplomacy and we aggressively continue to pursue structured engagements at both the county and national levels to address labour grievances and restore normalcy in our health facilities,” he said.Panyako said KNUN had given the Salaries and Remuneration Commission (SRC) a seven-day ultimatum, expiring later this month, to issue letters of no objection and sign pending CBAs. He warned that failure to resolve the issues could see the union escalate the strike to national referral hospitals.He said KNUN officials had held similar lengthy and strategic discussions with Homa Bay Governor Gladys Wanga, who serves as the CoG Chairperson for Human Resources, Labour and Welfare, and Nandi Governor Stephen Sang, who chairs the CoG Resource Mobilization and Partnerships Committee.Panyako said the direct involvement of the two governors was vital because Governor Wanga’s docket oversees human resource policies, CBAs and welfare frameworks for county employees across the 47 devolved units.He said Governor Sang’s position on resource mobilization was critical in unlocking external financing, partnerships and budgetary allocations needed to meet the union’s demands.The union signed the return-to-work formula in November 2017 to end a 150-day nationwide strike. Panyako said failure to implement core components of the agreement remained a major source of frustration among nurses and midwives. He said the consultations were aimed at bringing all relevant actors to the negotiating table and ensuring commitments made to health workers were honoured. He appealed to government agencies and county administrations to approach the matter with urgency and avoid further disruption of essential healthcare services, particularly for vulnerable patients in public hospitals.“By uniting the specific capabilities of the CoG Health, Labor, and Resource organs, this expanded consultative framework will create an essential pathway to finalize a comprehensive, financially backed deal that will decisively end the nationwide strike,” he said.Governor Nassir said devolved governments were committed to sustained engagements within the law to secure a fair and sustainable resolution to the industrial action.“We are appealing to the health workers to end the crippling strike and give dialogue a chance,” he said.The prolonged nurses’ and health workers’ strike has disrupted public health services in several counties, with reports of deserted hospital wards, patient discharges and congestion at major health facilities.
Read briefing As extreme heat becomes an increasingly visible reality across Japan, meteorologists, scientists, businesses and professional footballers are joining forces to encourage stronger climate action and raise awareness of the risks posed by global warming.A newly updated climate awareness initiative in Japan is drawing attention to what life could look like in 2050 if greenhouse gas emissions continue their current trajectory.The initiative, which has as its centerpiece the 2050 Weather Forecast video, comes as Japan grapples with increasingly severe heat. The newly introduced term kokushobi, or “extreme heat day”, describes days when temperatures reach 40°C or higher. Such conditions have regularly dominated national headlines, while reports that three lions died from heat stroke at a Tokyo Zoo have further highlighted the growing The new video updates an earlier forecast produced by Japan’s national broadcaster, NHK, in 2014 as part of a campaign by the UN’s World Meteorological Organization (WMO) which dramatically highlights how weather reports in 2050 will be characterized by extreme heat. Featuring the same weather forecaster and climate scientist, the latest version reflects both accelerating global warming and the latest scientific analysis.Several scenarios presented in the 2014 forecast have already become reality years earlier than anticipated. Among them are prolonged periods of temperatures exceeding 35°C, once presented as a potential future outcome for mid-century Japan.The updated forecast imagines conditions in 2050 under current climate policies.It projects that "extreme heat days" could be recorded in as many as 157 locations across the country. Measures to protect public health could include restrictions on outdoor activities, preventing children from playing outside and construction workers from carrying out work in open-air conditions.The video also warns of mounting pressures on food production and daily life. One example suggests that a popular Japanese pork cutlet rice dish could become a luxury item. It also highlights the possibility of increasingly destructive "super typhoons" bringing severe damage across the country.At the same time, the forecast points to solutions, including a faster transition to renewable energy and wider adoption of electric vehicles as part of the shift towards a decarbonized society.The initiative has been supported by the UN in Japan, and the video has been made freely available for public use.Its release comes amid growing calls for countries to strengthen efforts not only to cut emissions but also to protect communities from climate impacts already being felt today."Because even at full speed, we cannot outrun climate change," UN Secretary-General António Guterres said in a speech on 28 June.Professional football players are also helping bring the climate message to new audiences.Japan's professional football league, the J.LEAGUE, has introduced measures to reduce heat-related risks for both players and spectators, including adjusting match schedules to avoid the hottest parts of the day during increasingly hot and humid summers.The league has also partnered with the campaign I am one of the 89% who want to stop global warming, promoted jointly by the United Nations and Japanese media organizations.Six J.LEAGUE Climate Action Ambassadors have recorded video messages for the initiative, including Hiroki Yamada, a long-time star of Júbilo Iwata. In his message, Mr. Yamada expresses concern that children may increasingly be unable to play outdoors during summer and emphasizes the role individuals can play in addressing climate change.His message was shown on the giant screen at Júbilo Iwata's opening home match of the 2026/27 season on 8 August. The match kicked off at 7 pm as part of league-wide efforts to reduce heat-related risks.Organizers hope that reaching football supporters alongside wider audiences will help encourage greater public engagement on climate action at a time when the impacts of rising temperatures are becoming increasingly difficult to ignore.
Read briefing UN News reports that two peacekeepers were killed and seven people injured in an ambush in eastern Jonglei state. The incident underscores deteriorating security conditions and risks to civilian protection.Why it matters: Peacekeeper fatalities are a serious escalation indicator in a fragile conflict environment and can affect regional stability.
Read briefing Members of the minority ethnic Rohingya Muslim group in Myanmar are “suffering, misery, and cruelty on multiple levels and across the country that is heartbreaking,” according to the UN High Commissioner for Human Rights.Volker Türk was speaking as a new report was released by an independent UN fact-finding mission which found that human rights in the country – especially for minorities – have hit a new low.Myanmar is locked in a brutal civil war between the military and various resistance groups.In August 2017, Myanmar’s military conducted a ruthless crackdown on the Rohingya Muslims in the western Rakhine State, prompting more than 740,000 to flee across the border to Bangladesh, where the vast majority are still living as refugees.Five years since the military junta took control of Myanmar, it has killed at least 8,075 and forcibly conscripted hundreds of thousands while the rebel Arakan Army – the de facto authority across most of Rakhine – has committed widespread abuses against the Rohingya, according to the report.Covering June 2025 to May 2026, the new report details how an armed group’s August 2025 decision to stop supplying other anti-military groups allowed the military to press its advantage, going as far as to deny humanitarian aid in an effort to “crush opposition and force obedience.”The report describes the Rohingya as experiencing “systematic discrimination by all parties, with absolute impunity.”Having lost most of its control over Rakhine State to the Arakan Army, the military has resorted largely to airstrikes to stop rebel advances – often in civilian areas – with at least 2,592 of these strikes in the reporting period.The same military that killed thousands of Rohingya in 2017 has since forcefully conscripted around 125,000 – many of them Rohingya – subjecting some to forced alcohol consumption, denial of rest and physical abuse, according to the report.Despite its stated policy of “inclusive governance and equal treatment,” the Arakan Army rebels have seized land, forced Rohingyas to build their own prison-like detention camps, strictly controlled border crossings in Rakhine and arbitrarily killed and tortured many.Once detained by the Arakan Army, Rohingyas have reported being beaten with bamboo, burned with matches, hung upside down with their bodies spun until they passed out.They also reported having chili applied to their genitals and their fingernails removed. The Arakan Army reportedly forced one child to clear the bones and skulls of fellow Rohingya after a massacre.The report also outlines how since the 2021 coup, Myanmar has become the world’s largest producer of opium and synthetic drugs, alongside a multi-billion-dollar scam industry and the unregulated mining of rare earth minerals.In the absence of rule of law, these illicit economies have helped finance the conflict, strengthen transnational criminal networks and degrade Myanmar’s natural environment.Women and girls face entrenched gender inequalities and, in recent years, have been increasingly forced into the mining sector, putting them at heightened risk of sexual violence and reprisal if they spoke out, the report said.“Perpetrators were shielded from external scrutiny or legal recourse, strengthening impunity and allowing the systematic reoccurrence of sexual violence and labour exploitation,” the report read.Foreign nationals in managerial roles often exploit Burmese workers, forcing them into high-risk conditions and trapping them in debt bondage.Marking nine years since the since their forced mass displacement, Rohingya people in Myanmar, Bangladesh and across the region “face deepening insecurity, shrinking protection space and diminishing prospects for durable solutions, exacerbated by funding cuts impacting life-saving assistance,” UN Secretary-General António Guterres said on Tuesday.
Read briefing Kiharu MP Ndindi Nyoro has said he will take his campaign for national transformation across Kenya as he positions himself for the 2027 presidential race.
Read briefing After a ban over screwworm concerns, exporters are lining up to restart livestock shipments with tighter biosecurity oversight.Why it matters: A consequential agricultural trade story affecting supply chains, disease controls and cross-border farm income.
Read briefing Congo received a first shipment of more than 16,000 Ebola vaccine doses, with more deliveries expected as the outbreak spreads rapidly across affected provinces.Why it matters: Important in its own right, but it sits outside the 48-hour cutoff and overlaps with the newer vaccination report.
Read briefing AP says Congo’s outbreak is on track to become the deadliest on record, with cases and deaths rising faster than containment efforts can keep up.Why it matters: This remains a major continental health emergency with implications for travel, schooling and regional preparedness.
Read briefing The EastAfrican examines how local unrest and gang politics may foreshadow broader election-season volatility.Why it matters: Useful context for understanding political risk, mobilization tactics and security challenges ahead of Kenya's next general election.
Read briefing Kenya's government pushed back against calls for an external probe into rising political hostility and gang mobilization ahead of the 2027 election cycle.Why it matters: A live political-security storyline with direct relevance to governance, election integrity and public order in Kenya.
Read briefing Kenya is facing a growing problem of violence perpetrated by gangs, groups of youths and others co-opted by political elites and commonly referred to as ‘goons’.
Read briefing Rosemary Kimwatu Koech, Head of Data Protection at KCB Bank Group, has died, CIO Africa has learnt. She passed away at her home in Ngong on Friday morning. She was a well-known figure in Kenya’s technology, fintech, legal and data protection communities.Koech’s death brings to an end a career that spanned nearly two decades across law, public policy, technology, fintech and data protection, with her work increasingly focused on one of the most important issues facing organisations in the digital economy: how personal data is collected, processed and protected.The circumstances surrounding her death have not yet been disclosed. Her family is yet to issue a public statement on the cause of death.Koech joined KCB Bank Group in June 2022 as Data Protection Officer, transitioning from Safaricom PLC, where she had served as Public Policy Manager. She was subsequently appointed Head of Data Protection in June 2023, taking responsibility for the Group’s data protection compliance. Her move to KCB was reported by CIO Africa in 2022, when she announced the transition from Safaricom, describing it as a “season of growth and transition” and an opportunity to take on a new challenge.Before joining Safaricom in 2020, Koech had built a career that brought together legal expertise, public policy and the technology industry. She previously served as Head of Public Policy and Legal and Regulatory Specialist at Oxygène Marketing Communications, and held senior legal and regulatory roles at technology and fintech companies including WayaWaya and MODE.Her career began in marketing before she moved into industrial relations and legal practice. She subsequently worked as a Legal and Administrative Officer at Caritas Nairobi before moving into the technology sector.Beyond her corporate roles, Koech was deeply involved in Kenya’s wider technology ecosystem. At the time of her death, she served as a member of the Board of Trustees of KICTANet, a board member of the Association of Fintechs in Kenya and a director and board member at KeNIC TLD. She also chaired the Data Protection Working Group at the Kenya Bankers Association and served as an operational board member of Legal Hackers as a volunteer.These positions placed her at the intersection of some of Kenya’s most important digital policy conversations, including data protection, financial technology, internet governance, cybersecurity, regulation and the responsible use of technology.Koech’s career was notable for the way it evolved alongside Kenya’s rapidly changing digital economy. Her legal background gave her an understanding of regulation and governance, while her years working with technology companies, telecommunications and financial institutions put her close to the practical challenges created by digital transformation.This became particularly relevant as Kenya’s data protection framework developed and organisations began grappling with the requirements of the Data Protection Act and the growing importance of privacy and responsible data management.At KCB, she was part of the leadership responsible for navigating these issues within one of East Africa’s largest banking groups. But her influence extended beyond her day job. Through KICTANet, the Kenya Bankers Association, the Association of Fintechs in Kenya, KeNIC and other industry platforms, Koech participated in conversations that brought together technology companies, policymakers, regulators and other stakeholders.For many in Kenya’s technology community, she was therefore more than a data protection professional. She was part of a generation of professionals helping shape the rules and institutions around the country’s digital economy.Her academic and professional background reflected that intersection. Koech held a Bachelor of Laws degree from the University of Nairobi and an Advanced Diploma in Public Relations from the Chartered Institute of Public Relations.Her career demonstrated how legal expertise could be applied beyond traditional legal practice, particularly as technology increasingly became intertwined with regulation, public policy and business, earning her a place in our inaugural Most Influential Women in Digital Transformation list in 2020.Koech leaves behind a professional legacy in an area that has become increasingly central to Kenya’s digital future: ensuring that innovation and the use of data are accompanied by accountability, privacy and trust.At the time of publication, her family had not yet communicated details regarding funeral arrangements. CIO Africa will update this story as more information becomes available.
Read briefing Governor Johnson Sakaja, while calling on city residents to remain alert and proactive, said City Hall has intensified preparations and accelerated identification of hotspots.
Read briefing Kenyan organisations are facing a cyber threat environment that looks increasingly similar to what is being seen globally, but the biggest risks are often coming from vulnerabilities and security practices that have been known for years.The latest ESET Threat Report, which analyses threat activity since December 2025 using ESET telemetry and research, suggests that attackers are continuing to rely on familiar techniques such as malicious email attachments, phishing, outdated software and exposed remote desktop services. At the same time, artificial intelligence is becoming increasingly intertwined with the threat landscape, both as a target for attackers and as a tool for developing and carrying out attacks.ESET said it analysed around 900,000 AI skills globally, identifying more than 3,000 that were outright malicious. However, for Kenyan organisations, the more immediate concern may not be emerging AI-driven attacks but the continued effectiveness of conventional techniques.“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” says Allan Juma, Lead Cyber Security Engineer at ESET.Malicious email attachments continue to provide attackers with a relatively straightforward way into organisations. According to ESET, scripts accounted for 46.2% of malicious email attachments detected during the reporting period. Microsoft Office documents followed at 14.4%, PDFs at 11.9% and archives at 9.7%.Kenya broadly follows the same pattern, indicating that attackers do not necessarily need highly sophisticated techniques to compromise organisations. Instead, commonly used file formats and social engineering remain effective because employees continue to interact with them as part of their normal work.Another established technique is also becoming more prominent. QR code phishing, commonly known as “quishing”, reached record levels globally during the reporting period. About 11% of detected phishing emails contained a QR code, often directing victims to websites through their personal smartphones. The approach can be particularly useful to attackers because the victim may move from a corporate computer, where security controls are in place, to a personal mobile device that is subject to different protections.In Kenya, ESET telemetry recorded a 145% increase in quishing between the second half of 2025 and the first half of 2026. ESET cautions that the comparison is based on an incomplete baseline and should therefore be viewed as directional rather than a precise measure of growth.Kenya’s overall share of quishing activity remains below that of some major markets. North America, for example, accounted for 12.4% of detections, suggesting that the technique may still have considerable room to expand in Kenya.“QR codes have been adopted everywhere and are a convenience that attackers are counting on,” says Tony Anscombe, Chief Security Evangelist at ESET. “Many people still scan a QR code without stopping to consider where it leads.”Perhaps more significant for Kenyan organisations is the continued exploitation of vulnerabilities that should have been addressed years ago. ESET recorded more than a doubling of exploitation attempts against CVE-2017-0199 in Kenya between the second half of 2025 and the first half of 2026. The vulnerability affects outdated Microsoft Office installations and can allow malicious code to execute when a victim opens a specially crafted document.First disclosed in 2017, CVE-2017-0199 remains among the most frequently detected vulnerabilities globally in ESET’s latest report. It has also reportedly been incorporated into commercially available attack frameworks, including GhostX, which has been sold through dark web marketplaces. Its continued effectiveness in Kenya highlights a problem that extends beyond the vulnerability itself. For organisations running outdated software, an old vulnerability can remain a viable attack route long after security researchers and vendors have identified the weakness and issued fixes.The issue is also reflected in the exposure of remote desktop services. ESET found instances of remote desktop endpoints accessible from the public internet, including systems running versions of Windows that are no longer supported. Such systems can provide attackers with a direct path into an organisation when they have not been properly patched, secured or restricted.“The key takeaway is to do the basics,” says Juma. “Patch your endpoints, protect them at a minimum standard, and stop using default ports and passwords. Too much of what we are seeing comes down to organisations not doing the fundamentals.”The Kenyan threat landscape is also seeing increased activity from malware designed to steal information and deliver additional malicious payloads. ESET telemetry recorded a pronounced increase in Aotera, an infostealer and dropper that has become the fourth most frequently detected malware family in Kenya. Aotera can be used to deliver other malware, including AgentTesla, Formbook, PureLogs, PhantomStealer and Vidar. The connection is significant because the payloads being delivered in Kenya are not isolated threats. They include malware families that are already widely used internationally.
Read briefing Fragility is a design condition African Business
Read briefing