Skip to main content

Welcome to the Defthon





You’ve just stepped into the Defthon Blog — a space dedicated to continuous cybersecurity and digital defense. 
“Defthon” stands for Defence Marathon, reflecting our mission of staying vigilant, proactive, and always learning in the fast-paced world of cybersecurity.

Here, we share:

  • Insights on protecting digital assets and networks.

  • Tips, tutorials, and best practices for continuous security.

  • Updates on emerging threats and trends in cybersecurity.

  • Cybersecurity opportunities. 

  • Defence Strategies. 

  • Hackathons and CTFs

Whether you’re a cybersecurity professional, a tech enthusiast, or someone curious about digital defense, this blog is your go-to resource for non-stop learning and protection.

Join us on this marathon of defense, stay informed, and keep your digital world secure!

The Defthon Team



Comments

Post a Comment

Popular posts from this blog

Navigating Cloud Security - M-Tiba Case Study (Part 2)

  Disclaimer.  The views, assessments, and observations presented in this article are provided strictly for educational and analytical purposes, based on publicly available information and professional expertise. Defthon is not affiliated with, funded by, or acting on behalf of M-TIBA, any of its partners, competitors, government agencies, or any other stakeholder mentioned or implied. This analysis is vendor-neutral and non-partisan. It does not seek to assign blame, validate unverified claims, or reach definitive conclusions while official investigations are ongoing. All references to entities, systems, or potential impacts are intended solely to support high-level risk awareness, resilience building, and the advancement of cybersecurity best practices. Still referring to the case of  M-TIBA, the platform likely operates on a hybrid infrastructure with services distributed across multiple environments, including different cloud providers with diverse underlying technolo...

Cybersecurity in a Hybrid Health-Fintech - A case of M-TIBA (White Paper Series - Part 1)

Disclaimer. The views, assessments, and observations presented in this article are provided strictly for educational and analytical purposes, based on publicly available information and professional expertise. Defthon is not affiliated with, funded by, or acting on behalf of M-TIBA, any of its partners, competitors, government agencies, or any other stakeholder mentioned or implied. This analysis is vendor-neutral and non-partisan. It does not seek to assign blame, validate unverified claims, or reach definitive conclusions while official investigations are ongoing. All references to entities, systems, or potential impacts are intended solely to support high-level risk awareness, resilience building, and the advancement of cybersecurity best practices. Background Few weeks ago the news on M-TIBA PHI data leaked was all over where hackers claimed  to have stolen approx. 2.15 TB of data (17 million-plus files). M-Tiba is a mobile health wallet (Digital health financing platform) de...
 Understanding Phishing and Social Engineering in Today's Digital World In our increasingly connected world, cybercriminals have perfected the art of manipulation. They don't need to break down digital walls when they can simply trick you into opening the door. This is the essence of phishing and social engineering attacks that exploit human psychology rather than technical vulnerabilities. As one study notes, phishing emails utilize social engineering tactics to infuse a sense of urgency or fear in users, prompting them to take immediate action without verifying the message's authenticity . What is Phishing? The Digital Bait and Switch Phishing is a cyberattack where fraudsters send deceptive communications that appear to come from legitimate sources. The goal is simple: deceive recipients into disclosing sensitive information such as passwords, credit card numbers, or personal details, or into clicking on malicious links or downloading malware . Think of it as digital fis...
Addressing the Risk of Shadow AI in the Banking IT Environment The rapid adoption of artificial intelligence across banking operations has created an unprecedented challenge for IT and risk leadership: the emergence of Shadow AI.  While banks invest billions in sanctioned AI initiatives, employees are simultaneously deploying unsanctioned AI tools, models, and APIs across the enterprise often without IT oversight, governance, or security controls. This parallel adoption of AI outside formal governance frameworks presents one of the most pressing operational and compliance risks facing financial institutions today. Shadow AI is not a theoretical concern. It manifests daily in your organization: data analysts using ChatGPT for financial forecasting, customer service teams deploying third-party chatbots without security reviews, traders employing generative AI for market analysis outside approved systems, and risk teams leveraging unvetted machine learning models for cred...
  The Battle for Digital Sovereignty in Kenya’s Cloud Era: Critical Infrastructure, Banking, and FinTech Systems Kenya’s digital economy is one of the most advanced in Africa, driven by rapid innovation in fintech, mobile money, e-government services, and cloud adoption. Platforms like M-Pesa and national digital systems have positioned the country as a regional leader in digital transformation. However, beneath this success lies a growing structural risk: vendor lock-in in critical infrastructure systems . As government agencies, banks, telecom operators, and fintech companies increasingly rely on hyperscale cloud providers such as AWS, Microsoft Azure, and Google Cloud, they become deeply dependent on external ecosystems they do not fully control. This dependency raises serious concerns around: Digital sovereignty Cybersecurity resilience Regulatory compliance Long-term operational flexibility Cost escalation and bargaining power This article explores how vendor lock-in is shapi...