Dr Bright Gameli Mawudor, Chief Executive Officer of Cyber Guard Africa and founder of AfricaHackon / HANDOUTA nationwide passive assessment of Kenya’s cyber exposure has uncovered more than 2,000 critical vulnerabilities and over 4.8 million leaked credentials, exposing significant weaknesses across the country’s digital infrastructure.
The first-of-its-kind national threat landscape study analysed 13 Autonomous System Numbers (ASNs), which are unique identification numbers assigned to large networks or groups of IP networks operating under a single routing policy.
Dr Bright Gameli Mawudor, Chief Executive Officer of Cyber Guard Africa and founder of AfricaHackon unveiled the findings, during the 2026 Cybersecurity Summit held from August 27 to 29 at Hackhouse Africa in Nairobi.
Cyber Guard Africa and the AfricaHackon team conducted the study jointly as part of efforts to understand Kenya’s cyber threat landscape and identify weaknesses that could expose organisations and individuals to cyberattacks.
Mawudor said the findings demonstrated that Kenya remains highly vulnerable to cyber threats and that urgent action was needed to improve the country's cyber resilience.
“We are very vulnerable based on the research we did,” Mawudor said.
The assessment examined a wide range of vulnerabilities across Kenya’s digital environment, including email system misconfigurations, firewall and VPN exposure, virtualisation weaknesses and exposed application programming interfaces (APIs).
Researchers also examined the security of Internet of Things (IoT) devices, Wi-Fi networks, cloud systems and databases, as well as publicly exposed server credentials.
The more than 2,000 critical vulnerabilities identified in the assessment point to weaknesses that could potentially be exploited by malicious actors if left unaddressed.
The discovery of more than 4.8 million leaked credentials also highlights the scale of information that has already been exposed publicly and the risks faced by organisations and individuals whose login details may have been compromised.
“These findings below show the states of why the conference needed to happen and ways to get the country into a Cyber Resilient state,” Mawudor said.
The assessment was conducted entirely through passive techniques, meaning researchers did not actively interfere with or exploit the systems they assessed.
“All assessment activity was conducted passively,” the organisers said.

A full report detailing the findings, recommended remediation measures and governance guidance for organisations across the country is expected to be published.
The findings will also form part of the evidence base informing cybersecurity programming and activities arising from this year's summit.
Mawudor said AfricaHackon would increase practical training opportunities to help cybersecurity professionals and other practitioners develop the skills required to address real-world threats.
“A lot more hands on workshops will be done by Africahackon to give the ability to people to apply skill to curb real world cyber threats,” he said.
The organisers have also released a series of portals intended to help members of the public, cybersecurity professionals and organisations improve their security.
The platforms provide cybersecurity professionals with opportunities to practise their skills in controlled and safe environments while learning techniques for securing systems.
One of the initiatives provides an intensive six-month hands-on cybersecurity training programme that has expanded to 21 countries.
Another platform is designed to help organisations identify, prioritise, validate and remediate cyber threats before they become more serious.
The organisers have also established a public intelligence platform intended to provide information on emerging threats and guidance on how individuals and organisations can identify them within their own environments.
The initiatives come at a time when organisations are increasingly dependent on digital systems, cloud platforms, connected devices and online services, expanding the potential attack surface for cybercriminals.
The summit was held under the theme “From Skills to Securing Systems”, reflecting a shift towards practical cybersecurity capabilities and long-term resilience rather than relying solely on traditional conference discussions.
This year's AfricaHackon summit adopted a different format from conventional cybersecurity conferences, replacing panel-heavy sessions with interactive workshops and clinics.
The organisers described the approach as “unconferencing the conference”, placing practitioners at the centre of discussions and practical exercises.
The summit brought together security practitioners, chief information security officers, developers, policymakers and regulators seeking to address cybersecurity challenges at scale.
The organisers said the rapid evolution of cyber threats, particularly the use of artificial intelligence by attackers to automate malicious activity, means technical skills alone are no longer sufficient.
“As cyber threats evolve at machine speed, accelerated further by adversaries automating attacks with AI, technical skill alone is no longer enough,” the organisers said.