Polish Web Under Threat: Security Experts Discover Vulnerabilities in Courts, Hospitals, and Airports

A pair of security researchers from Poland have raised alarms regarding the vulnerability of the nation’s internet infrastructure to cyber threats, uncovering thousands of public agencies and websites that are at risk.
At the recent Def Con cybersecurity conference in Las Vegas, researchers Robert Kruczek and Kamil Szczurowski shared their motivations for investigating the cybersecurity landscape in Poland: a sense of national duty and a commitment to enhancing safety online for all citizens.
Their investigation led to the discovery of over 10,000 public entities affected, with around 250,000 websites exhibiting security weaknesses, including critical infrastructures like airports, hospitals, and government offices.
The researchers attributed these vulnerabilities to flawed software from vendors and insufficient mechanisms for reporting security issues, which collectively jeopardize public services in Poland. They highlighted that some of the identified weaknesses were alarmingly easy to exploit and often dismissed by vendors as mere inconveniences.
This research is particularly timely as Poland seeks to enhance its cybersecurity posture following a series of suspected cyberattacks from Russian sources targeting vital sectors such as energy and water. Many of these incidents exploit existing security gaps.
Among the critical vulnerabilities discovered was one within the popular content management system Pad CMS, which enabled the researchers to access over 300 public websites without any authentication. The software had not been updated as it was no longer supported.
Additionally, another vulnerability granted access to roughly two-thirds of Poland’s judiciary system, affecting around 245 courts, according to their findings.
The researchers reported their discoveries to governmental authorities through various official channels, aiming to prompt action against the vulnerabilities they found.
Despite the challenges faced during their investigation, they expressed optimism, noting that their efforts have made the digital landscape “a little bit more safe.”



