Tech

Polish researchers expose critical vulnerabilities in public sector digital infrastructure

Security experts Robert Kruczek and Kamil Szczurowski present data showing widespread flaws in government systems, including unsecured court databases and unsupported software, amid heightened regional cyber tensions.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Def Con findings reveal over 10,000 entities and 250,000 websites at risk

Security researchers Robert Kruczek and Kamil Szczurowski have revealed that more than 10,000 public entities and approximately 250,000 websites in Poland are susceptible to cyberattacks. Presented at the Def Con cybersecurity conference in Las Vegas, the findings highlight significant vulnerabilities across the nation’s public sector, including critical infrastructure such as courts, hospitals, and airports.

The researchers conducted the scan driven by a sense of patriotism and a desire to improve the safety of Poland’s public web. Their investigation identified common points of failure, particularly within the Pad CMS content management system, which is widely used to organise and display web content. The software developer had ceased support for the product, describing it as end of life, which prevented the patching of critical vulnerabilities.

One specific flaw in the Pad CMS system allowed unauthorised access to approximately 245 courts, representing two-thirds of Poland’s judiciary, without the need for a password. Additionally, the researchers identified critical vulnerabilities in another web system that enabled access to over 300 public websites without authentication. These flaws stemmed from unsupported software and a notable absence of bug bounty programmes or formal mechanisms for reporting security flaws.

Kruczek and Szczurowski noted that some of the identified bugs were incredibly easy to exploit, yet they were not always prioritised by those responsible for the systems. Some vendors reportedly dismissed bug reports as inconveniences, highlighting a procedural gap in handling security risks. The duo reported their findings to the Polish government through various official channels, stating that the effort contributed to improved national security.

The disclosure comes as Poland strengthens its cyber defences following a wave of suspected Russian attacks targeting the country’s energy and water providers. Previous incidents have exploited weak cybersecurity measures, underscoring the urgency of addressing these systemic vulnerabilities. The researchers concluded that their work, though challenging, had made the nation a little bit safer.

Continue reading

More from Tech

Read next: Screwworm infestations surge in Mexico as human cases exceed 500
Read next: New Mexico Judge Orders Meta to Pay $567 Million for Youth Mental Health Abatement
Read next: Walmart-sponsored gaming site Restart cuts editorial staff