
Two Polish security researchers say a broad scan of their country’s public web uncovered security weaknesses affecting more than 10,000 public entities and about 250,000 websites, including airports, hospitals, courts, and government offices. The findings, presented at Def Con in Las Vegas on Friday, suggest that widely used software flaws and weak reporting channels are leaving parts of Poland’s public sector exposed to hijacks and other attacks.
What the researchers set out to learn
Robert Kruczek and Kamil Szczurowski said they launched the project out of patriotism and a desire to make Poland’s internet safer. Their goal was simple: understand how vulnerable the country’s public web might be to cyberattacks and see what could be done to reduce the risk.
That effort quickly escalated into a much larger picture of exposure than they expected. By the time their work was complete, they said they had identified thousands of affected organizations and a very large number of vulnerable websites.
What they found across Poland’s public web
According to the researchers, the scan turned up more than 10,000 affected public entities and around 250,000 websites with security flaws. The list included sensitive institutions such as airports, hospitals, and government offices, showing that the problem was not limited to obscure or low-priority sites.
The pair said some of the weaknesses were tied to buggy software supplied by vendors, while others were made worse by a lack of bug bounty programs or simple ways to report flaws. In their view, that combination creates a setup where serious problems can persist long after they should have been fixed.
Easy-to-exploit bugs, but not always treated seriously
Kruczek and Szczurowski also said some of the bugs were surprisingly easy to exploit, yet vendors did not always respond with urgency. In some cases, they said, the reports were treated more like inconveniences than security problems that could lead to real-world harm.
That attitude matters because public-sector websites often sit at the edge of critical services. A compromised site can become a foothold for deeper intrusion, a tool for misinformation, or a way to disrupt access to important public functions.
The Pad CMS flaws stood out
One of the clearest problems the researchers identified involved Pad CMS, a widely used content management system. They said critical vulnerabilities in the platform let them access more than 300 public websites without using a password.
The software developer did not patch the issue because Pad CMS had already reached “end of life” and was no longer supported. That detail underscores a common cybersecurity problem: organizations can remain dependent on outdated systems even after vendors stop maintaining them.
A separate issue reached Poland’s courts
The researchers said another bug let them access the websites of roughly two-thirds of Poland’s judiciary, or about 245 courts. That scope makes the flaw especially notable, since judicial systems often handle sensitive information and are high-value targets for attackers.
While the researchers did not describe the bug in greater technical detail in the source material, they said the impact was broad enough to affect a large portion of the country’s court websites. The findings suggest that a single weakness can ripple across many institutions when platforms are widely shared.
Why the timing matters for Poland
The research arrives as Poland is trying to strengthen its cyber defenses following a wave of suspected Russian hacks aimed at the country’s energy and water providers. Some of those incidents reportedly relied on weak cybersecurity, adding urgency to efforts to harden public systems.
Against that backdrop, the researchers’ findings point to a familiar challenge: protecting critical infrastructure is not only about defending high-profile networks, but also about keeping the everyday web services used by public agencies in good repair.
Reporting the problems to the government
Kruczek and Szczurowski said they reported their findings to the Polish government through official channels. They also said the process was worth the effort, because it made the country “a little bit more safe.”
That outcome reflects one of the central tensions in security research. Large-scale scanning can reveal uncomfortable truths, but it can also give governments and vendors a chance to clean up systems before attackers exploit them.
What this tells us about public-sector security
- Legacy software remains a major risk: Unsupported systems can leave entire groups of websites exposed if they remain in use after end of life.
- Disclosure paths matter: Without bug bounties or straightforward reporting channels, vulnerabilities may linger longer than necessary.
- Scale amplifies small flaws: A single weakness in a shared platform can affect hundreds of sites at once.
- Public services are attractive targets: Courts, hospitals, airports, and agencies can all become stepping stones for broader attacks.
The researchers’ work does not mean every affected site was actively breached, but it does suggest that a significant slice of Poland’s public web was exposed to avoidable risk. In a country already dealing with cyber pressure on critical infrastructure, the findings are a reminder that digital maintenance can be as important as frontline defense.
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: August 10, 2026 at 4:50 pm
2 views

