ESET Research has released its latest Threat Report summarising how the threat environment has changed since December 2025, drawing on ESET telemetry and the analysis of its threat detection and research teams. Globally, the report describes a period in which artificial intelligence has become both a target for attackers and how they carry out attacks, with ESET analysing around 900,000 AI skills and finding more than 3,000 to be outright malicious. For Kenyan organisations, however, the more useful reading of the data is that the local threats are not exotic. They are the same techniques seen elsewhere, applied locally, and the exposure they exploit owes more to unaddressed fundamentals than to novelty.
“The threats facing Kenya are the same around the world, and email remains one of the most reliable ways of getting ransomware into the organisation,” says Allan Juma, Lead Cyber Security Engineer at ESET. The report found that malicious email attachments continue to do all the work and are dominated by scripts (46.2%), followed by Microsoft Office documents (14.4%), PDFs (11.9%) and archives (9.7%). Kenya conforms to the same distribution, with the methods remaining popular because they are effective.
QR code phishing, or “quishing”, has reached record levels globally, with around 11% of all detected phishing emails carrying a QR code in the reporting period, often moving the victim onto a personal mobile device that sits outside corporate defences. In Kenya, ESET telemetry recorded a 145% increase in quishing between the second half of 2025 and the first half of 2026, although the comparison spans an incomplete baseline and is best treated as directional rather than precise. In absolute terms, Kenya’s share remains well below that of the largest markets, such as North America at 12.4%, which suggests…
Source link
Read Full Article by TechTrends at techtrends.africa
Source link
