The duo presented their findings at the Def Con conference in Las Vegas, detailing how a combination of outdated software and unresponsive vendors leaves essential services open to exploitation. Among the most significant discoveries was a vulnerability in the Pad CMS platform, which granted unauthorized access to more than 300 public websites without requiring a password. Because the software has reached its end-of-life stage, developers have ceased providing security patches, leaving the affected entities indefinitely exposed.
In section Startups & Technology
Polish public infrastructure left exposed by widespread software flaws
Thousands of Polish public institutions, including airports, hospitals, and judicial offices, remain vulnerable to cyberattacks due to systemic security failures. Researchers Robert Kruczek and Kamil Szczurowski uncovered over 250,000 compromised websites, exposing critical gaps in how the nation manages its digital defenses against potential state-sponsored threats.

Beyond content management systems, the researchers identified a flaw affecting two-thirds of the country’s judiciary, potentially impacting roughly 245 courts. These findings emerge as Poland works to fortify its energy and water sectors following a series of suspected Russian-linked cyber incursions. While Kruczek and Szczurowski reported these defects through official government channels, they noted a prevailing culture of indifference among some software vendors who dismissed security warnings as mere inconveniences. The researchers argue that the absence of formal bug bounty programs further exacerbates the risk, hindering the ability to identify and remediate vulnerabilities before they are weaponized.
Comments (0)
No comments yet. Be the first!