← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Polish security researchers find thousands of public entities vulnerable to cyberattacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Over 10,000 public entities and 250,000 websites in Poland have security flaws.
  • Vulnerabilities found in airports, hospitals, government offices, and judiciary systems.
  • Bugs in Pad CMS allowed access to over 300 public websites without passwords.
  • Some vendors dismissed bug reports as inconveniences.

Widespread Vulnerabilities Discovered

Security researchers Robert Kruczek and Kamil Szczurowski presented findings at Def Con detailing extensive cybersecurity vulnerabilities across Poland's public internet. Their research uncovered more than 10,000 public entities and 250,000 websites with security flaws, affecting critical services such as airports, hospitals, and government offices.

Specific Flaws and Vendor Response

The researchers identified issues stemming from buggy software from various vendors and a lack of bug bounty programs or clear reporting mechanisms. One significant finding involved critical vulnerabilities in Pad CMS, a widely used content management system. These flaws allowed access to over 300 public websites without requiring a password. The developer of Pad CMS did not patch the software, stating it was 'end of life' and no longer supported.

Impact on Judiciary and Public Services

Another vulnerability discovered by Kruczek and Szczurowski granted them access to the websites of approximately two-thirds of Poland's judiciary, encompassing about 245 courts. The researchers noted that some easily exploitable bugs were not taken seriously by vendors, who sometimes described the bug reports as mere inconveniences.

Context of National Cybersecurity

This research comes as Poland is actively working to strengthen its cyber defenses following a series of suspected Russian cyberattacks targeting its energy and water providers. Some of these previous attacks exploited existing cybersecurity weaknesses. The researchers reported their findings to the Polish government through official channels, aiming to contribute to national security improvements.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Two Polish security researchers identified over 10,000 public entities with 250,000 websites containing security flaws, including critical infrastructure like airports, hospitals, and government offices. This discovery highlights significant cybersecurity weaknesses in Poland's public sector, particularly concerning given recent suspected Russian cyberattacks targeting the country.