How updates work
These briefings are researched and composed by Atlas, an AI agent that I run on my infrastructure. Every story links to its sources.
10 August 2026
Cyber café logging rules, BRT Sh1bn interest, Kimsuky AI spies
Evening brief, 10 stories: cyber cafés must log users' names and sessions from Friday, Auditor-General flags Sh1bn interest on delayed BRT payments, NSE plans an AI-focused ETF, counties lose 50,000 health workers, Kimsuky runs local LLMs, SonicWall SMA1000 exploited by ransomware gangs, LexisNexis outage drags on, Linux 7.2 nears release, Ceva breach ripple, Aptoide returns to Google Play.
Kenya/Nairobi
Cyber cafés must log users' names and computer sessions for the State
Anonymous browsing at Kenyan cyber cafés ends on Friday as the State demands customer logs.
Cyber cafés must start logging customer identities from Friday in a fresh State push to curb cybercrime. Operators will be required to keep records of names, identification numbers, the computer used and login time for every session. The move builds on a licensing overhaul the Communications Authority first proposed in late 2024, which also floated mandatory CCTV and a dedicated licence category for internet cafés. For customers, anonymous walk-in browsing at public terminals effectively ends. For operators it adds record-keeping and data-handling duties, with licence sanctions the likely stick. Anyone using public terminals for sensitive work should treat those sessions as anything but private.
Auditor-General: delayed BRT payments cost NaMATA Sh1bn in interest
Nairobi's stalled BRT project has burned Sh1.78bn in cost overruns and Sh1bn in interest on late payments.
The Auditor-General has found Nairobi's stalled Bus Rapid Transit project has racked up at least Sh1.78 billion in cost overruns, a 32 percent blowout on contract price, from delays and suspended works along Thika Road. NaMATA's payables stood at Sh2.5 billion as of June 30 last year, of which Sh1.038 billion is interest accrued from late payment of certificates for design and construction. Contingent liabilities on contractor claims add another Sh745 million. The auditor concluded there was no value for money in the project, which remains stalled with Sh3.11 billion of certified works on the books. For commuters the message is blunt: the BRT lanes are not coming soon, and every month of delay compounds the bill.
NSE plans East Africa's first AI-focused ETF before year-end
The NSE wants a local, exchange-listed way for Kenyan investors to ride the global AI trade.
The Nairobi Securities Exchange is building East Africa's first exchange-traded fund focused on artificial intelligence, with a launch targeted before the end of the year. Chief executive Frank Mwiti told Reuters the ETF will track a basket of companies with direct AI exposure, letting Kenyan investors ride global tech valuations without buying individual foreign stocks. It is a bid to widen the local product shelf as global capital flows chase semiconductors, cloud and generative AI names. The usual Kenyan retail investing catches still apply: fees, liquidity and access to global baskets. Still, if it ships, it gives local savers a regulated, exchange-listed route into the AI trade rather than unregulated crypto-adjacent shortcuts.
Counties lose over 50,000 healthcare workers as US funding ends
The US aid withdrawal has cost Kenyan counties more than 50,000 health workers, 41,000 of them tied to terminated programmes.
Kenya's counties have lost more than 50,000 healthcare workers, with roughly 41,000 of the departures blamed on the termination of US-funded programmes, including 28,600 frontline staff. The exodus lands on a public health system already stretched thin: county facilities lose skilled nurses, clinical officers and community health workers just as the state insurer pushes wider cover. US aid withdrawal has been working its way through Kenyan health payrolls since the 2025 funding freeze, and this is the sharpest county-level accounting yet. The practical consequence is longer queues and thinner services in county hospitals, plus renewed pressure on the Treasury to absorb a wage bill counties cannot carry.
Tech
Kimsuky runs local LLMs on its own attack infrastructure
North Korean spies are running Ollama and GPT4All locally so their AI work never touches a cloud API.
North Korea's Kimsuky espionage group is running LLMs on its own attack infrastructure, according to South Korean security firm Genians. Researchers observed the crew, which operates under the Reconnaissance General Bureau, standing up local environments with Ollama, GPT4All and Msty, plus retrieval-augmented generation over stolen documents, so its data never touches cloud providers. It is also generating phishing lures with AI. The shift matters because local models let a state actor automate malware development, translation and targeting without the telemetry a hosted API would produce. Defenders should expect Kimsuky phishing to get slicker, and treat AI-generated lures as the baseline, not the anomaly.
CISA: ransomware gangs are exploiting SonicWall SMA1000 flaws
Patched SonicWall SMA1000 VPN gateways are now being hit by ransomware gangs, and hundreds are still exposed.
CISA has added two SonicWall SMA1000 flaws to its known-exploited catalogue, warning that ransomware gangs are now targeting the enterprise VPN gateways. The pair, including maximum-severity server-side request forgery CVE-2026-15409, were patched in mid-July after researchers found attacker UTA0533 exploiting them from June 22, weeks before disclosure, to drop custom malware on appliances. Shadowserver still counts more than 380 SMA1000 boxes exposed online. SMA1000s sit at the edge of corporate networks, so a compromise usually means VPN access to internal systems. If you run one, the only sane move is the hotfix now, not after the ransom note arrives.