Two Polish security researchers, Robert Kruczek and Kamil Szczurowski, have uncovered thousands of public agencies and websites in Poland at risk of cyberattacks. Their findings, presented at the Def Con cybersecurity conference in Las Vegas on Friday, revealed more than 10,000 affected public entities with 250,000 websites exhibiting security flaws.
The vulnerabilities were found across various public services, including airports, hospitals, and government offices. The researchers attributed some of these risks to buggy software from vendors and a reported lack of bug bounties or clear channels for reporting security flaws.
Critical vulnerabilities were identified in the widely used content management system Pad CMS. This allowed access to over 300 public websites without a password. The software developer reportedly did not patch the software, stating it was "end of life" and no longer supported. Additionally, another bug reportedly granted access to the websites of approximately two-thirds of Poland's judiciary, affecting about 245 courts.
The researchers reported their findings to the Polish government through official channels, stating that their work has made the country "a little bit more safe." This research comes as Poland reportedly seeks to strengthen its cyber defences following suspected Russian hacks targeting energy and water providers, some of which exploited weak cybersecurity.