IT-PUB NEWS

Polish researchers reveal cyber risks at public sites

09.08.2026 12:03 • Author: IT-PUB
Polish researchers reveal cyber risks at public sites

At Def Con, two researchers said they found flaws affecting more than 10,000 public entities in Poland, including courts, hospitals and airports.

Two Polish security researchers say a scan of the country’s public web uncovered a striking number of vulnerable sites, including those run by courts, hospitals and airports. Their findings, presented at the Def Con cybersecurity conference in Las Vegas, point to basic weaknesses in public-facing systems that can still put essential services at risk. According to IT-PUB News, the researchers described the work as an attempt to understand how exposed Poland’s public web is to cyberattacks. The scale they reported went well beyond a handful of isolated cases.

Robert Kruczek and Kamil Szczurowski said they carried out the project out of patriotism and a desire to make Poland’s internet safer. They said they found more than 10,000 affected public entities and 250,000 websites with security flaws. 

A scan found weaknesses across public institutions

The researchers said they wanted to measure how exposed Poland’s public web might be to cyberattacks. Their scan quickly turned up a large number of sites with security issues across public institutions.

Among the affected entities were airports, hospitals and government offices. These are not just ordinary websites. They often act as entry points to services people use every day, from public information to administrative systems.

What drew attention was the breadth of the findings. A single scan revealed weaknesses across a wide range of institutions, suggesting the problem was not confined to one sector or one type of organization.

Old software and weak reporting paths added to the risk

Kruczek and Szczurowski said part of the problem came from buggy vendor software, along with the lack of bug bounties and clear ways to report security flaws. In their view, that left Poland’s public services more exposed to hijacks and other attacks.

They also said some of the bugs were very easy to exploit, but were not always treated as serious. In some cases, vendors reportedly described bug reports as inconveniences rather than urgent security issues.

That matters because cyber risk is not just about whether a flaw exists. It also depends on how quickly it is taken seriously and fixed. When reporting channels are weak, even simple vulnerabilities can stay open longer than they should.

One of the clearest examples involved Pad CMS, a widely used content management system. The researchers said they found critical vulnerabilities in it that allowed them to access more than 300 public websites without a password. The software developer did not patch the issue because the product had reached “end of life” and was no longer supported.

Court websites were among the systems exposed

The researchers said another bug gave them access to websites used by about two-thirds of Poland’s judiciary, or roughly 245 courts. That makes the finding especially sensitive, since court systems are part of the digital infrastructure that supports public trust and the functioning of the state.

The source does not say whether the vulnerabilities affected internal systems or only public websites. Even so, access to public-facing court sites can still be disruptive. It can open the door to defacement, misinformation or other forms of abuse if attackers discover the same weaknesses.

The presence of hospitals and airports among the affected entities raises similar concerns. In those cases, website security is not just a technical matter — it can shape how people get information, reach services and judge whether institutions are reliable online.

The findings come as Poland faces cyber pressure

The research comes as Poland is trying to strengthen its cyber defenses after a wave of suspected Russian hacks targeting energy and water providers. Some of those attacks, the source says, involved weak cybersecurity.

That backdrop helps explain why the findings drew attention. They do not describe a purely abstract threat. They point to vulnerabilities in a country already dealing with cyber pressure on critical infrastructure.

Kruczek and Szczurowski said they reported their findings to the government through official channels. During their talk, they said the effort was worth it because it made the country “a little bit more safe.”

Their work underscores a familiar but often neglected problem: public institutions can be put at risk not only by sophisticated attacks, but also by outdated software, unsupported systems and slow responses to basic security flaws.

 


Аудит Сайту для малого та середнього бізнесу за $50