Researchers Discover Over 10,000 Vulnerable Public Entities in Poland
Two Polish security researchers scanned their country's public web and found over 10,000 vulnerable entities, including airports, hospitals, and courts. They presented their findings at Def Con and revealed critical flaws in the Pad CMS system, exposing Poland to potential cyberattacks.
- They discovered 250,000 websites with security flaws in Poland, affecting more than 10,000 public entities.
- The unsupported Pad CMS content management system allowed access without a password to over 300 government sites.
- The researchers identified vulnerabilities in 66% of the Polish judiciary, including 245 courts.
Polish security researchers Robert Kruczek and Kamil Szczurowski undertook a patriotic mission to assess the security of Poland's public web. At the Def Con conference in Las Vegas, they revealed that their scan found over 10,000 vulnerable public entities, with 250,000 websites having critical flaws.
The findings include airports, hospitals, and government offices. The duo explained that the errors were easily exploitable but were not taken seriously by the providers.
Context: A Wave of Russian Attacks
The research comes at a time when Poland is facing a wave of alleged Russian cyberattacks targeting its energy and water suppliers. These attacks have precisely exploited the weak cybersecurity that has now been documented.
Kruczek and Szczurowski sought to understand the state of the public web out of patriotism and the desire to make it more secure. Their work revealed an alarming situation for a country in the midst of escalating geopolitical tensions.
The researchers found that some errors were incredibly easy to exploit, raising the risk of public service hijacking. This situation jeopardizes the country's critical infrastructure.
Vulnerabilities in Pad CMS
The Pad CMS content management system, widely used by Polish websites to organize and display content, was a critical focus of vulnerabilities. The software had reached its 'end of life' and no longer received support, leaving important patches unaddressed.
The researchers identified critical vulnerabilities in Pad CMS that allowed them to access over 300 public websites without needing a password. The developer did not patch the software because it had stopped maintaining it, leaving users unprotected.
Another flaw found allowed them to access the websites of approximately two-thirds of the Polish judiciary, about 245 courts. This unauthorized access could enable attackers to manipulate judicial information or disrupt legal services.
The exposure of these vulnerable systems represents a significant risk, especially in the context of cyber conflicts with Russia. Attackers could exploit these flaws to launch ransomware attacks or steal sensitive data.
Kruczek and Szczurowski reported their findings to the Polish government through various official channels. In their talk, they stated that the effort was worth it, as a result, we are 'a little bit safer'.
Reaction from Authorities and Providers
The investigation highlights the lack of a security culture in Polish public administration. The absence of bug bounty programs and responsible disclosure processes discourages researchers from reporting flaws constructively.
The researchers pointed out that some providers dismissed bug reports as 'inconveniences', an attitude that contrasts with the seriousness of the vulnerabilities. This behavior puts millions of citizens who rely on digital public services at risk.
The Pad CMS example demonstrates the dangers of using software without active support. Many public institutions rely on outdated systems that do not receive security updates, creating backdoors for cybercriminals.
The Polish government has intensified its cybersecurity efforts, but this study shows that there is still much work to be done. Implementing responsible disclosure policies and updating software are urgent steps.
Implications for National Security
The research comes at a time of high tension, with cyberattacks attributed to Russia against Polish critical infrastructure. The vulnerabilities found could be exploited by state actors to destabilize the country.
Unauthorized access to courts, airports, and hospitals could lead to service disruptions and manipulation of judicial data. The risk is tangible and not limited to information exposure, but also includes the possibility of destructive attacks.
The researchers demonstrated that even with basic tools, entire systems can be compromised. Their systematic scanning of the Polish public domain is a clear warning to other nations that may face similar issues.
The response from authorities will be key to restoring trust in digital security. Measures such as creating bug bounty programs and migrating to actively maintained software are essential.
Kruczek and Szczurowski not only identified the problems but also offered solutions. Their official report praised the effort, although they insisted that structural changes are needed to protect public services.
Lessons for the Global Community
The case of Poland is a reminder that cybersecurity is not a luxury but a necessity in the digital age. Public institutions must prioritize cybersecurity as part of their responsibility to citizens.
The lack of software maintenance and the absence of reporting mechanisms are common problems in many countries. This research offers a model for assessing and improving a nation's security posture.
Responsible disclosure by researchers is an example of how the security community can contribute to public welfare. Despite the risks, their work has reduced Poland's exposure to potential attacks.
The recommendation is clear: governments must invest in cybersecurity, train their staff, and foster collaboration with external experts. Only then can the multiplying threats in cyberspace be mitigated.
The work of Kruczek and Szczurowski not only protects Poland but also serves as a warning to other countries with fragile digital infrastructures. Security is an ongoing effort that requires constant attention and adequate resources.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Cypherpunk Technologies launches Zcash mining fleet with 33.33 million Winklevoss deal

Record Gold Prices Boost Optimism Among Options Traders!

Dollar: Government maintains exchange barrier and the city projects a moderate increase by the end of the year

AI: Minnesota Accuses Grok of Facilitating Digital Sexual Violence

Central Banks Want Crypto Plumbing, But Not Cryptocurrencies

Will 540 Million Tokens Be Confiscated? OP Governance Vote in Internal Conflict
![[Alpha Analysis] Peter Thiel Allocates 72% of Portfolio to Energy... The Bottleneck of AI Investment Shifts](/public-static/7_ca1b7746d1.png?format=avif)
[Alpha Analysis] Peter Thiel Allocates 72% of Portfolio to Energy... The Bottleneck of AI Investment Shifts

Curve founder says FATF pressure could make DeFi safer and more decentralized

Bitcoin: The Next Bottom Could Arrive in October 2026

Exits MENA and ACE Local Management Fully Acquire Avanz Capital Egypt

Polymarket’s 20% CLARITY Act odds sit on a market one $100K trade could radically reprice

Bitcoin Holds at $64,000 as Yields Surge: What Explains This?

18th Anniversary of the bitcoin.org Domain Registration

Jensen Huang, Ultraman, and Masayoshi Son: A 20-Year Alliance

Bitcoin: 28,000 BTC Return to Exchanges in Less Than Three Weeks

Crypto: Donald Trump's popularity drops to 33%, what are the consequences for the sector?

Buying an Apartment in a New Building Before Winter: How to Avoid Being Left Without Heat, Water, and Electricity

Kraken brings US stock trading to European Economic Area customers

Robinhood Chain Growth: +45% But Not Thanks to Tokenized Stocks

UBS Research on China's AI Industry Chain: Large Models Accelerate Iteration, Funds Begin to Flow to Semiconductors

Five Months Before Its Implementation, the U.S. Stablecoin Law Still Seeks Its Operating Manual

Failed Crypto Exchange in the Netherlands: 12 Million Invested, Only 2 Million Recovered

DDR4 Price Increase Expected to Continue into Q4, Maintaining 'Attractive' View on Greater China Semiconductor Industry

Hermes Bot Mode Officially Integrated, Supporting AI Group Collaboration

Web3: South Korean Retail Investors Shift to US Stocks, Focusing on AI Semiconductor Targets

When AI Borrows Money from Wall Street: The Tech Giants' 'CapEx Cycle' Accelerates Financialization

Private Sector Contraction Deepens: Employer Companies Decreased by 3.3% Year-on-Year

U.S. Stock Market May Achieve Nearly 30 Years Without Extreme Sell-Offs in 2026

Franklin Expands XRP Position to 225 Million, Cardano Sets Upgrade Plan Until 2027








