Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks


Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked.

At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand the state of Poland’s public web out of a sense of patriotism and a desire to make it safer for everyone. 

Before long, the duo discovered more than 10,000 affected public entities with 250,000 websites with security flaws, including airports, hospitals, and government offices. 

The researchers found that some of the vendors’ buggy software, coupled with a lack of bug bounties and ways to report security flaws, are putting Poland’s public services at risk of hijacks and other attacks. The researchers also said that some bugs were incredibly easy to exploit but were not always taken seriously, with some vendors describing the bug reports as inconveniences.

The research comes as Poland is trying to shore up its cyber defenses after a wave of suspected Russian hacks targeting the country’s energy and water providers. Some of the hacks have been carried out by taking advantage of weak cybersecurity. 

Kruczek and Szczurowski found critical vulnerabilities in the widely used content management system Pad CMS, which allowed them to easily access over 300 public websites without needing a password. The software developer did not patch the software because it had become “end of life” and was no longer supported.

Another bug allowed them to gain access to the websites of some two-thirds of Poland’s judiciary, or about 245 courts, they said.

The duo reported their findings to the government through various official channels.

The researchers said during their talk that it was ultimately worth the hassle, saying that as a result we are “a little bit more safe.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.



Source link

  • Related Posts

    An Anthropic Model Submitted A False Homicide Tip To Philadelphia Police

    The tip thankfully landed in the department’s spam folder. Ann Kapustina/Shutterstock Philadelphia police appear to have been caught in one of the most bizarre cases of “rogue” AI…

    Continue reading
    Strands Hint Today: Answers for Oct. 10, No. 951

    Here’s your NYT Strands hint for today, plus the spangram and all of today’s Strands answers for puzzle No. 951 on Saturday, Oct. 10, 2026. Today’s theme was kind of…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    An Anthropic Model Submitted A False Homicide Tip To Philadelphia Police

    An Anthropic Model Submitted A False Homicide Tip To Philadelphia Police

    Don’t worry, Valve: I’ve got your next Deadlock character concepts sorted

    Don’t worry, Valve: I’ve got your next Deadlock character concepts sorted

    Absolute Security Acquires Phoenix Technologies’ FirmGuard to Build on the Firmware Foundation Enterprises Need for Secure, Compliant, and Resilient AI

    Suspect arrested in FBI hack that exposed employee information

    Suspect arrested in FBI hack that exposed employee information

    Sikandar Raza leads Zimbabwe in Richard Ngarava absence at UAE tri-series

    Sikandar Raza leads Zimbabwe in Richard Ngarava absence at UAE tri-series

    Strands Hint Today: Answers for Oct. 10, No. 951

    Strands Hint Today: Answers for Oct. 10, No. 951