HomeTechnologySecurity researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

TechnologyAugust 7, 2026
2 min read
Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites.
Reading Settings

Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks, and quickly found that thousands of public agencies and websites were at risk of being hacked.

At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand the state of Poland’s public web out of a sense of patriotism and a desire to make it safer for everyone. 

Before long, the duo discovered more than 10,000 affected public entities with 250,000 websites with security flaws, including airports, hospitals, and government offices. 

The researchers found that some of the vendors’ buggy software, coupled with a lack of bug bounties and ways to report security flaws, are putting Poland’s public services at risk of hijacks and other attacks. The researchers also said that some bugs were incredibly easy to exploit but were not always taken seriously, with some vendors describing the bug reports as inconveniences.

The research comes as Poland is trying to shore up its cyber defenses after a wave of suspected Russian hacks targeting the country’s energy and water providers. Some of the hacks have been carried out by taking advantage of weak cybersecurity. 

Kruczek and Szczurowski found several bugs in the widely used content management system Pad CMS, which website owners use to organize and display content.

The two found critical vulnerabilities in one web system called Pad CMS, which allowed them to easily access over 300 public websites without needing a password. The software developer did not patch the software because it had become “end of life” and was no longer supported.

Another bug allowed them to gain access to the websites of some two-thirds of Poland’s judiciary, or about 245 courts, they said.

The duo reported their findings to the government through various official channels.

The researchers said during their talk that it was ultimately worth the hassle, saying that as a result we are “a little bit more safe.”

Source: TechCrunch

Share this article

Related Articles

WhatsApp Gets a Handy @all Feature for Group Chats
Aug 086 hours ago

WhatsApp Gets a Handy @all Feature for Group Chats

A new software update builds on WhatsApp’s group chat chops by adding anonymous polls and introducing an easier way to start a smaller private chat away from the larger group.

6a7514f3c54c7af3b242074e4 min read
Read More
Spokane Shows What the New Era of Wildfires Looks Like
Aug 086 hours ago

Spokane Shows What the New Era of Wildfires Looks Like

With rising temperatures and drier conditions, fires are more likely to explode. And with more people living next to forests, the results can be catastrophic.

6a763fd54aedcde7771f17cb6 min read
Read More