All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Polish web infrastructure at risk of hacks, researchers find

Created at 7 Aug · 9:21 PM1 source↑ Market-relevant
IN SHORT

Security researchers discovered over 10,000 public entities in Poland, including courts, hospitals, and airports, are vulnerable to cyberattacks due to outdated software and poor security reporting mechanisms. The findings highlight significant risks to public services.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

10,000+public entities at risk
250,000websites with security flaws
245courts affected
2/3of Poland's judiciary affected

Who's Involved

Robert Kruczek
Polish security researcher
Kamil Szczurowski
Polish security researcher
Pad CMS
Content management system with critical vulnerabilities
Polish web infrastructure at risk of hacks, researchers find

↳ Why This Matters

The widespread vulnerabilities in Poland's public sector infrastructure expose critical services like hospitals and airports to potential cyberattacks, posing risks to national security and public safety. The findings underscore the urgent need for improved cybersecurity practices and vendor accountability in protecting essential public services.

Key facts

  • Over 10,000 Polish public entities and 250,000 websites were found to be at risk of hacking.
  • Vulnerabilities were identified in systems like Pad CMS, with some bugs allowing access without passwords.
  • Affected entities include airports, hospitals, and government offices, with a significant portion of the judiciary impacted.
  • Researchers attribute the risks to outdated software, lack of bug bounty programs, and vendors dismissing security reports.
  • The findings were reported to the Polish government, aiming to improve national cyber defenses.
  • Polish security researchers Robert Kruczek and Kamil Szczurowski have uncovered significant cybersecurity risks across Poland's public sector, identifying over 10,000 public entities and 250,000 websites vulnerable to hacking. The findings, presented at the Def Con cybersecurity conference, highlight issues stemming from outdated software, such as the Pad CMS, and a lack of robust mechanisms for reporting and addressing security flaws.

    The researchers discovered critical vulnerabilities that allowed them to access hundreds of public websites without passwords, including those of airports, hospitals, and government offices. Notably, approximately two-thirds of Poland's judiciary, comprising about 245 courts, were found to be affected by these security weaknesses.

    Kruczek and Szczurowski noted that some vendors dismissed bug reports as inconveniences, exacerbating the risk of hijacks and other cyberattacks. This research emerges at a critical time for Poland, which has been bolstering its cyber defenses following a series of suspected Russian-linked hacks targeting its energy and water infrastructure.

    The duo reported their findings through official government channels, expressing hope that their work contributes to making the country's digital infrastructure safer.

    Frequently asked questions

    The research identified critical vulnerabilities in content management systems like Pad CMS, which allowed easy access to public websites. These issues affected entities including airports, hospitals, and government offices.

    Researchers discovered over 10,000 public entities and 250,000 websites with security flaws, impacting a significant portion of Poland's public services.

    Vulnerabilities stem from outdated and unsupported software, coupled with a lack of bug bounty programs and inadequate channels for vendors to address reported security flaws.

    The findings come as Poland is working to strengthen its cyber defenses following a series of suspected Russian-linked cyberattacks targeting the country's energy and water providers.

    What Happens Next

    01Polish government to implement patches and security updates for affected systems.
    02Vendors to address reported vulnerabilities and improve security reporting channels.
    03Further research to assess the extent of exploitation of discovered bugs.

    Get the newsletter.

    Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

    Cadence

    How It Developed

    Two Polish security researchers aimed to assess the vulnerability of Poland's public web infrastructure.
    They identified over 10,000 public entities and 250,000 websites with security flaws.
    Vulnerabilities were found in outdated software like Pad CMS, allowing easy access to public websites.
    Bugs affected approximately two-thirds of Poland's judiciary, including about 245 courts.
    Researchers cited buggy vendor software and a lack of bug bounty programs as contributing factors.
    Findings were reported to the Polish government through official channels.
    The research comes amid suspected Russian cyberattacks targeting Polish energy and water providers.

    Sources

    T1
    Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacksTechCrunch

    Related Stories

    China's Kimi K3 AI model bypassed UK security test sandbox
    7 Aug · 8:39 AM
    Framework notifies customers of data breach following Metabase hack
    7 Aug · 4:16 PM
    US Companies Face Rising Tide of AI-Driven Cyberattacks
    7 Aug · 11:54 AM
    Explainer: Who is liable when AI goes rogue? Lawyers see new risks
    7 Aug · 10:09 AM
    Remembering the pre-Google web, when search was an experiment
    7 Aug · 11:06 AM