
Tony Anscombe, Chief Security Evangelist at cybersecurity firm ESET.
Kenyan organisations are being targeted mostly through old, avoidable weaknesses rather than new or advanced techniques, a new report by cybersecurity firm ESET has found.
Attacks targeting a Microsoft Office weakness first identified nine years ago, known as CVE-2017-0199 (Common Vulnerabilities and Exposures), more than doubled in Kenya between the second half of 2025 and the first half of 2026, ESET’s data shows.
The flaw allows malicious code to run when a victim opens a specially designed document. ESET says the vulnerability has been incorporated into off-the-shelf attack frameworks such as GhostX, which are sold on dark web marketplaces.
QR (Quick Response) code phishing, known as “quishing”, also jumped 145 per cent in Kenya over the same period. ESET cautions that the figure should be treated as directional because the comparison is based on an incomplete baseline.
Globally, about 11 per cent of phishing emails detected during the reporting period carried a QR code. The technique often redirects victims to their mobile phones, potentially taking them outside the security controls protecting their work computers. Kenya’s share remains below North America’s 12.4 per cent, suggesting the technique has room to grow locally.
“QR codes have been adopted everywhere and are a convenience that attackers are counting on,” said Tony Anscombe, ESET’s chief security evangelist. “Many people still scan a QR code without stopping to consider where it leads.”
Email remains another major route into organisations, with malicious attachments continuing to be used to deliver ransomware and other threats.