Briev
Live
Technology

Polish security analysts uncover thousands of vulnerable public websites at Def Con

Researchers Robert Kruczek and Kamil Szczurowski revealed that over 10,000 Polish public entities and 250,000 sites have exploitable security flaws, including courts, hospitals and airports.

During a presentation at the Def Con cybersecurity summit, Robert Kruczek and Kamil Szczurowski disclosed the results of a systematic scan of Poland’s public-sector web presence. Their investigation found that over 10,000 government bodies and roughly 250,000 websites suffer from security deficiencies, exposing sectors such as the judiciary, healthcare, and aviation to potential compromise. A notable vulnerability in the legacy Pad CMS allowed unrestricted access to more than 300 sites, while another flaw granted entry to about two-thirds of the country’s courts.

The researchers attributed the problem to obsolete software, insufficient reporting mechanisms, and the absence of bug-bounty incentives. They have forwarded their findings through official Polish channels, aiming to prompt remediation as the country strengthens its defenses after a series of suspected Russian cyber intrusions.

Why it matters

Weaknesses in public-sector websites could enable attacks on essential services, threatening national security and citizen safety.

In this story

cybersecuritypublic sectorvulnerable websitesPad CMSbug bountyRussian hackscourt systemshospital networksairport infrastructure