Two Polish cybersecurity researchers revealed significant vulnerabilities affecting thousands of critical public institutions across their country. After conducting a comprehensive scan of Poland’s web infrastructure, Robert Kruczek and Kamil Szczurowski discovered that over 10,000 public entities operated websites containing serious security flaws, presenting substantial risks to essential services.
The investigation, presented at the Def Con cybersecurity conference in Las Vegas, identified particular dangers in widely-used content management software. One platform called Pad CMS contained critical vulnerabilities that granted unauthorized access to more than 300 public websites without requiring passwords. Most alarmingly, the researchers exploited another vulnerability that exposed approximately 245 court systems, representing roughly two-thirds of Poland’s entire judiciary.
The researchers attributed these widespread security gaps to flawed vendor software combined with the absence of effective bug reporting mechanisms and security incentive programs. Some software developers reportedly dismissed vulnerability reports as minor inconveniences rather than legitimate concerns, while others failed to provide security patches for outdated systems no longer officially supported.
The findings carry particular urgency given Poland’s recent history of suspected Russian cyberattacks targeting energy and water infrastructure. Despite the challenges of reporting their discoveries through official government channels, Kruczek and Szczurowski emphasized the importance of their work in improving national cybersecurity.