Polish security researchers Robert Kruczek and Kamil Szczurowski revealed at the Def Con conference in Las Vegas on Friday that thousands of Poland’s public websites—including airports, hospitals, and judicial networks—are highly vulnerable to devastating cyberattacks due to critical software flaws.
A Patriotic Mission Exposes Massive Digital Vulnerabilities
Driven by patriotism and a desire to bolster national security, the research duo embarked on a comprehensive scan of Poland’s public web infrastructure. What they uncovered was a digital security nightmare: more than 10,000 public entities, spanning a massive network of 250,000 websites, are currently riddled with severe security flaws.
This widespread vulnerability comes at a critical time for Poland. The nation is actively working to fortify its cyber defences following a series of suspected Russian cyberattacks targeting vital energy and water providers, many of which exploited similarly weak security protocols.
Critical Vulnerabilities in Key Infrastructure
During their investigation, Kruczek and Szczurowski identified glaring security loopholes in widely used software. Chief among these was a critical vulnerability in the widely used content management system Pad CMS. This specific flaw allowed the researchers to bypass security entirely and gain passwordless access to over 300 public websites. Worryingly, the software developer declined to patch the vulnerability, citing that the product had reached its “end of life” status and was no longer supported.
Judicial and Public Services Left Exposed
The vulnerabilities extended deep into the country’s legal infrastructure. The researchers discovered another security bug that granted them access to the internal websites of approximately 245 courts, representing nearly two-thirds of Poland’s entire judiciary system. Along with judicial networks, critical transport hubs like airports and healthcare facilities like hospitals remain dangerously exposed to external hijackings and malicious intrusions.
A Systemic Failure in Cybersecurity Response
According to the researchers, the danger is compounded by a lack of standardised bug bounty programmes and official channels to report these security flaws. Many of the bugs they discovered were incredibly simple to exploit, yet software vendors frequently failed to take the warnings seriously, sometimes dismissing the vulnerability reports as mere inconveniences.
Despite the resistance, the duo systematically reported their extensive findings to the Polish government through multiple official channels. Reflecting on their challenging journey during their Def Con presentation, the researchers emphasised that their efforts were entirely worth the trouble, noting that their disclosures have ultimately made the public web a little bit safer for everyone.
