Two Polish security researchers set out to assess how vulnerable their country’s public internet infrastructure was to cyberattacks. What they discovered was a far larger problem than expected, with thousands of public institutions and websites potentially exposed to hackers.
At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski explained that their investigation was driven by both patriotism and a desire to make Poland’s public-facing internet safer.
Their research uncovered more than 10,000 affected public entities and approximately 250,000 websites containing security weaknesses. Among the organizations potentially exposed were airports, hospitals, government offices, and other public institutions.
The researchers attributed many of the vulnerabilities to flawed software used by vendors, combined with limited systems for reporting security problems and a lack of bug bounty programs. They said some of the vulnerabilities were remarkably easy to exploit, yet were not always treated seriously by the companies responsible for the software. In some cases, vendors reportedly dismissed security reports as little more than inconveniences.
The findings come at a particularly sensitive time for Poland, which has been working to strengthen its cyber defenses following a series of suspected Russian cyberattacks targeting critical infrastructure, including energy and water providers. Some of those attacks have reportedly taken advantage of weak cybersecurity protections.
During their investigation, Kruczek and Szczurowski identified multiple vulnerabilities in Pad CMS, a widely used content management system that organizations rely on to create, manage, and publish website content.
One of the most serious vulnerabilities they discovered affected a particular Pad CMS web system and allowed the researchers to gain unauthorized access to more than 300 public websites without requiring a password. The software developer ultimately did not patch the vulnerability because the product had reached “end of life” and was no longer officially supported.
The researchers also uncovered another vulnerability that they said provided access to websites belonging to roughly two-thirds of Poland’s judiciary, representing approximately 245 courts.
The scale of the exposure demonstrated how a single vulnerable software platform can potentially put large numbers of public institutions at risk, particularly when outdated systems remain in use after vendors stop providing security updates.
Kruczek and Szczurowski reported their findings to Polish authorities through several official channels in an effort to ensure the affected organizations could address the problems.
Despite the difficulties involved in reporting the vulnerabilities and dealing with organizations that did not always take the findings seriously, the researchers said their work was ultimately worthwhile.
As they put it during their presentation, the investigation left Poland “a little bit more safe.”



