Truth that Matters. Stories that Impact

Truth that Matters. Stories that Impact

Technology

Thousands of Polish Public Websites Vulnerable to Cyberattacks, Researchers Reveal at Def Con

Security researchers have revealed widespread cybersecurity vulnerabilities across thousands of public sector websites in Poland, exposing critical infrastructure and institutions to potential cyberattacks.

What Happened

Speaking at the Def Con cybersecurity conference in Las Vegas on Friday, Polish security researchers Robert Kruczek and Kamil Szczurowski presented findings from their broad evaluation of Poland’s public internet. The duo aimed to assess the vulnerability of public websites out of a stated desire to enhance national security and protect public infrastructure.

Their scan revealed security flaws across more than 250,000 websites tied to over 10,000 public entities. The exposed systems spanned vital public services, including hospitals, airports, municipal government offices, and judicial bodies.

Key Highlights

  • Massive Exposure: More than 10,000 public entities and 250,000 websites were identified with security weaknesses.
  • Critical Judicial Flaw: A security vulnerability gave researchers access to websites belonging to roughly two-thirds of Poland’s judiciary, encompassing approximately 245 courts.
  • Pad CMS Vulnerabilities: Flaws in the widely deployed Pad CMS allowed direct access to over 300 public websites without requiring passwords. The developer did not fix these vulnerabilities because the software had reached its end-of-life status.
  • Reporting Challenges: The researchers noted a lack of bug bounty programs and established reporting mechanisms, with some software vendors dismissing security reports as inconveniences.
  • Official Notifications: The researchers submitted their discoveries through formal government reporting channels to facilitate remediation.

Why This Matters

The findings emerge as Poland works to strengthen its cyber defenses following a series of suspected Russian cyber operations targeting essential services, including energy and water utilities. Kruczek and Szczurowski pointed out that inadequate cybersecurity practices, unpatched legacy software, and a lack of receptive reporting channels leave public infrastructure exposed to hostile hijacks and intrusions.

What to Watch Next

Following the submission of these vulnerabilities to official government channels, attention turns to how Polish authorities and public agencies address legacy software issues, improve reporting avenues, and secure critical infrastructure from potential exploitation.

Frequently Asked Questions

Who conducted the cybersecurity scan of the Polish web?

The investigation was conducted by Polish cybersecurity researchers Robert Kruczek and Kamil Szczurowski, who presented their results at the Def Con conference in Las Vegas.

What types of institutions were affected?

The vulnerabilities impacted thousands of public entities, notably hospitals, airports, municipal offices, and approximately 245 courts across the country.

Why were some software flaws left unpatched?

In the case of Pad CMS, which exposed over 300 websites without password protections, the software developer declined to issue patches because the product had reached end-of-life and was no longer supported.

Source: TechCrunch