Skip to main content

Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

Two Polish security researchers discovered that thousands of public agencies, courts, hospitals, and websites across the country are vulnerable to cyberattacks.

AI-written
Inewgen
08 Aug 2026Source: TechCrunch3 min read (0 views)Last updated 29 Aug 2026
Share
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

Stock photo for illustration only, not from the actual event

Font size
  • Two researchers scanned Poland's public web to assess national cybersecurity.
  • They found over 10,000 public entities and 250,000 websites with security flaws.
  • Outdated CMS software and unsupported programs contributed heavily to the risks.

Two security researchers in Poland set out to investigate how vulnerable their nation's internet infrastructure was to potential cyberattacks, quickly uncovering that a vast number of public agencies and websites were at immediate risk of being hacked.

Speaking at the Def Con cybersecurity conference in Las Vegas on Friday, researchers Robert Kruczek and Kamil Szczurowski explained that their assessment of Poland's public web was driven by a sense of patriotism and a commitment to making digital systems safer for everyone.

Conducting large-scale security scans of national public infrastructure is a critical exercise that exposes hidden vulnerabilities before malicious actors can exploit them. However, it also highlights the widespread systemic risks of relying on legacy software, outdated content management systems, and underfunded public sector IT maintenance.

Before long, the duo identified more than 10,000 affected public entities with 250,000 websites containing security flaws, including high-profile critical infrastructure such as airports, hospitals, and government offices.

10,000+Affected Public Entities
250,000Websites with Flaws

The researchers noted that buggy vendor software, combined with an absence of bug bounty programs and clear reporting channels for security flaws, is leaving Poland's public services exposed to hijacks and various cyber threats. They also pointed out that certain vulnerabilities were astonishingly easy to exploit yet frequently dismissed by vendors who treated the vulnerability reports as mere inconveniences.

This research arrives as Poland attempts to reinforce its cyber defenses following a wave of suspected Russian cyberattacks targeting the country's energy and water infrastructure, some of which succeeded by exploiting weak cybersecurity protocols.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

Poland government building digital security

Stock photo for illustration only, not from the actual event

Kruczek and Szczurowski uncovered multiple bugs in Pad CMS, a widely utilized content management system that website operators rely on to organize and display digital content. Critical vulnerabilities in the platform allowed them to easily access over 300 public websites without requiring a password, as the software developer had ceased issuing patches after the product reached its "end of life" status.

"A little bit more safe."

Robert Kruczek and Kamil Szczurowski

An additional bug enabled the pair to gain unauthorized access to websites representing roughly two-thirds of Poland's judiciary system, equating to approximately 245 courts. Following their discoveries, the duo submitted their findings to the government through official reporting channels.

Source: TechCrunch

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article