Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
AI-summarised brief · reviewed before publication
Polish security researchers Robert Kruczek and Kamil Szczurowski scanned the nation’s public web and identified more than 10,000 vulnerable entities across 250,000 sites, including airports, hospitals, courts and government offices. Their findings, presented at the Def Con conference in Las Vegas, highlighted critical flaws in the Pad CMS content‑management system that granted unauthenticated access to over 300 sites, and a separate bug that exposed roughly two‑thirds of Poland’s judiciary—about 245 courts. The duo traced many weaknesses to outdated vendor software, absent bug‑bounty programs and inadequate reporting mechanisms, which they say led to dismissive responses from some providers. They have forwarded the data to Polish authorities, urging remediation to strengthen the country’s cyber defenses amid recent suspected Russian attacks on energy and water infrastructure.
💡 Why It Matters
- · The uncovered flaws expose essential public services to easy hijacking, forcing Poland to confront systemic security gaps before adversaries exploit them.