Two Polish security researchers have discovered widespread vulnerabilities affecting thousands of public agencies, including hospitals, courts, and airports. Presented at the Def Con conference in Las Vegas, the findings revealed that roughly 250,000 websites across 10,000 public entities suffered from serious cybersecurity flaws.
The investigation highlighted issues such as unpatched, end-of-life software like Pad CMS, which allowed unauthorized access without credentials, and exposed about two-thirds of Poland’s courts. According to the researchers, many software vendors failed to take vulnerability reports seriously, dismissing them as mere inconveniences rather than addressing critical risks.
This discovery underscores the challenges Poland faces in securing its critical infrastructure amid ongoing concerns over state-sponsored cyberattacks targeting energy and water utilities. The researchers have officially reported the flaws to the government to help improve national cyber defenses.
- Over 250,000 vulnerable websites found across 10,000 Polish public entities.
- Hospitals, airports, and courts were among the critical institutions at risk.
- Outdated software and unresponsive vendors exacerbated the security gaps.
- Researchers reported the issues to the government to bolster cyber defense.
Sources:
