Security Researchers Scan Polish Web, Find Courts, Hospitals, and Airports at Risk of Hacks

critical infrastructurecybersecuritydef conpad cmspolandpublic sectorsecurity researchweb vulnerabilities
Two Polish security researchers set out to assess the vulnerability of their country's internet infrastructure to cyberattacks, uncovering a startling reality: thousands of public agencies and websites are exposed to potential breaches. Speaking at the Def Con cybersecurity conference in Las Vegas on Friday, researchers Robert Kruczek and Kamil Szczurowski explained that their motivation was patriotic—a desire to make Poland's digital landscape safer for all citizens. Their investigation revealed more than 10,000 affected public entities, encompassing 250,000 websites with security flaws, including those of airports, hospitals, and government offices. The researchers identified several root causes: buggy software from various vendors, a lack of bug bounty programs, and limited channels for reporting security issues. These factors collectively place Poland's public services at risk of website hijacking and other malicious attacks. Alarmingly, some vulnerabilities were trivially easy to exploit, yet vendors often dismissed the reports as mere inconveniences rather than serious threats. This research is particularly timely, as Poland has been bolstering its cyber defenses following a wave of suspected Russian hacks targeting the country's critical infrastructure—including energy providers and water treatment plants. Some of these attacks have succeeded by exploiting weak cybersecurity measures. A key focus of the research was Pad CMS, a widely used content management system that helps website owners organize and display content. Kruczek and Szczurowski discovered critical vulnerabilities in this system, which allowed them to access over 300 public websites without requiring a password. The software developer had ceased patching Pad CMS, declaring it "end of life" and no longer supported. Another significant flaw enabled the researchers to gain unauthorized access to the websites of roughly two-thirds of Poland's judiciary—about 245 courts. The duo reported their findings to government authorities through official channels. Despite the bureaucratic challenges, they expressed satisfaction with the outcome, stating that their efforts have made the country "a little bit more safe." This work highlights the ongoing challenges in securing public digital infrastructure, especially as geopolitical tensions continue to drive cyber threats.

via TechCrunch

Related