Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Two Polish security researchers discovered that thousands of public agencies, courts, hospitals, and websites across the country are vulnerable to cyberattacks.

Stock photo for illustration only, not from the actual event
- Two researchers scanned Poland's public web to assess national cybersecurity.
- They found over 10,000 public entities and 250,000 websites with security flaws.
- Outdated CMS software and unsupported programs contributed heavily to the risks.
Two security researchers in Poland set out to investigate how vulnerable their nation's internet infrastructure was to potential cyberattacks, quickly uncovering that a vast number of public agencies and websites were at immediate risk of being hacked.
Speaking at the Def Con cybersecurity conference in Las Vegas on Friday, researchers Robert Kruczek and Kamil Szczurowski explained that their assessment of Poland's public web was driven by a sense of patriotism and a commitment to making digital systems safer for everyone.
Conducting large-scale security scans of national public infrastructure is a critical exercise that exposes hidden vulnerabilities before malicious actors can exploit them. However, it also highlights the widespread systemic risks of relying on legacy software, outdated content management systems, and underfunded public sector IT maintenance.
Before long, the duo identified more than 10,000 affected public entities with 250,000 websites containing security flaws, including high-profile critical infrastructure such as airports, hospitals, and government offices.
The researchers noted that buggy vendor software, combined with an absence of bug bounty programs and clear reporting channels for security flaws, is leaving Poland's public services exposed to hijacks and various cyber threats. They also pointed out that certain vulnerabilities were astonishingly easy to exploit yet frequently dismissed by vendors who treated the vulnerability reports as mere inconveniences.
This research arrives as Poland attempts to reinforce its cyber defenses following a wave of suspected Russian cyberattacks targeting the country's energy and water infrastructure, some of which succeeded by exploiting weak cybersecurity protocols.

Stock photo for illustration only, not from the actual event
Kruczek and Szczurowski uncovered multiple bugs in Pad CMS, a widely utilized content management system that website operators rely on to organize and display digital content. Critical vulnerabilities in the platform allowed them to easily access over 300 public websites without requiring a password, as the software developer had ceased issuing patches after the product reached its "end of life" status.
"A little bit more safe."
Robert Kruczek and Kamil Szczurowski
An additional bug enabled the pair to gain unauthorized access to websites representing roughly two-thirds of Poland's judiciary system, equating to approximately 245 courts. Following their discoveries, the duo submitted their findings to the government through official reporting channels.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment