Poland’s Public Services Vulnerable to Cyberattacks Due to Software Flaws
Two Polish security researchers conducted a comprehensive scan of Poland’s public internet infrastructure and discovered significant vulnerabilities across thousands of government websites, healthcare systems, and critical facilities. During their presentation at the Def Con conference in Las Vegas, Robert Kruczek and Kamil Szczurowski revealed that over 10,000 public entities were affected, with 250,000 websites containing exploitable security flaws. The researchers highlighted how outdated software like Pad CMS, which lacks support and updates, created easy entry points for cyberattacks. They found critical vulnerabilities allowing access to over 300 public websites without passwords and two-thirds of Poland’s judiciary systems. The findings come amid ongoing efforts to bolster cybersecurity after suspected Russian attacks on energy and water providers. Vendors often dismissed bug reports as minor issues, contributing to systemic risks. The researchers emphasized the importance of proactive security measures and reporting mechanisms to protect essential services from potential hijacks.
