Polish Courts, Hospitals, and Airports Found Vulnerable to Hacking in Security Scan

0
2

Key Takeaways

  • Polish security researchers Robert Kruczek and Kamil Szczurowski identified >10,000 public entities and ≈250,000 websites with security flaws.
  • Critical bugs in the outdated Pad CMS allowed password‑free access to over 300 public sites and to roughly two‑thirds of Poland’s judiciary (≈245 courts).
  • Many vendors treated serious vulnerability reports as inconveniences and failed to patch end‑of‑life software, amplifying risk.
  • The findings were reported through official channels; researchers stressed that responsible disclosure made Poland “a little bit more safe.”
  • The work highlights the need for systematic bug‑bounty programs, timely patching, and stronger cyber‑defense policies amid rising Russian‑linked threats to critical infrastructure.

Introduction and Motivation
At the Def Con cybersecurity conference in Las Vegas, Polish security researchers Robert Kruczek and Kamil Szczurowski presented a sobering assessment of their nation’s public‑facing web assets. Motivated by a blend of patriotism and a genuine desire to protect citizens, the duo set out to gauge how vulnerable Poland’s governmental and municipal websites truly are. Their goal was not merely academic; they hoped to uncover weaknesses that could be exploited by hostile actors and to spur remediation before any damage occurred. By framing their work as a civic duty, they underscored the importance of independent security research in safeguarding national digital infrastructure.

Scope of the Discovery
The researchers’ scanning efforts revealed a startling landscape: more than 10,000 distinct public entities—ranging from city halls and ministries to schools and utility operators—operated roughly 250,000 websites that exhibited detectable security flaws. This breadth indicates that the problem is not isolated to a few rogue servers but permeates the entire public sector ecosystem. The sheer volume of affected sites suggests systemic shortcomings in how Polish institutions procure, maintain, and monitor their web platforms.

Nature of the Vulnerabilities
Among the identified weaknesses, many stemmed from outdated or poorly configured software components, insufficient input validation, and missing security headers. Some vulnerabilities were classified as “critical” because they permitted remote code execution or unauthorized administrative access without requiring any authentication. The researchers noted that several of these flaws were trivially exploitable—attackers could leverage them with simple scripts or publicly available exploit kits—yet they remained unaddressed for extended periods.

Pad CMS Findings
A focal point of the investigation was the widely used content management system Pad CMS. The researchers uncovered two severe bugs in this platform. First, a flaw allowed them to bypass authentication entirely, granting unfettered access to the administrative backend of any site running the vulnerable version. Second, another bug enabled them to enumerate and retrieve sensitive configuration files, potentially exposing database credentials and other secrets. Because Pad CMS had been declared “end of life” by its developer, no official patches were forthcoming, leaving countless sites perpetually exposed.

Impact on Judiciary and Public Services
Perhaps the most alarming implication emerged from the judiciary sector. The researchers reported that the Pad CMS vulnerability gave them access to the websites of approximately two‑thirds of Poland’s courts—about 245 judicial institutions. Such access could enable attackers to alter case documents, leak confidential legal information, or disrupt court proceedings. Beyond the judiciary, similar weaknesses were found in hospital portals, airport information systems, and municipal service sites, amplifying the potential harm to essential public functions.

Vendor Response and Software End‑of‑Life
When the researchers notified the vendors responsible for Pad CMS and other affected software, the reactions were often dismissive. Several vendors characterized the bug reports as “inconveniences” rather than urgent security issues, reflecting a troubling undervaluation of vulnerability disclosure. Because the problematic versions had reached end‑of‑life status, vendors declined to invest in patches, opting instead to advise customers to migrate to newer products—a solution that many public agencies lacked the resources or planning to implement promptly.

Reporting Process to Authorities
Undeterred by vendor indifference, Kruczek and Szczurowski pursued formal reporting routes. They submitted detailed vulnerability reports to Poland’s Computer Security Incident Response Team (CSIRT), relevant ministries, and sector‑specific regulatory bodies. The researchers emphasized the importance of using established channels to ensure that findings reached the appropriate decision‑makers and could trigger coordinated remediation efforts, including emergency patches, system isolations, or mandatory upgrades.

Broader Cybersecurity Context in Poland
The disclosure comes amid heightened concern over cyber threats emanating from Russian state‑aligned actors, who have recently targeted Poland’s energy grid, water treatment facilities, and telecommunications infrastructure. Many of those intrusions leveraged basic security gaps—exactly the type of flaws highlighted by the researchers. Consequently, the Pad CMS discoveries are not isolated anomalies but symptomatic of a broader deficiency in cyber‑hygiene that could be exploited in larger‑scale campaigns aimed at destabilizing critical services.

Researchers’ Reflection and Call to Action
During their Def Con talk, Kruczek and Szczurowski acknowledged the frustration of navigating bureaucratic inertia and vendor apathy but stressed that the effort was worthwhile. They argued that each responsibly disclosed vulnerability contributes incrementally to national resilience, making Poland “a little bit more safe.” The duo urged government agencies to adopt mandatory bug‑bounty programs, enforce strict patch‑management policies for public‑facing software, and prioritize the retirement or securing of legacy systems. They also called on the private sector to treat vulnerability reports with the seriousness they deserve, recognizing that collaborative defense benefits all stakeholders.

Conclusion and Key Implications
The work of Robert Kruczek and Szczurowski shines a stark light on the fragility of Poland’s public web infrastructure. By exposing thousands of vulnerable sites—including vital judicial and health‑service portals—through easily exploitable bugs in abandoned software like Pad CMS, they have highlighted urgent gaps in procurement, maintenance, and incident‑response practices. Their experience demonstrates that responsible disclosure, even when met with resistance, can drive measurable improvements in security posture. Moving forward, Poland must institutionalize proactive vulnerability management, sustain funding for timely software updates, and foster a culture where security researchers are viewed as partners in national defense rather than nuisances. Only through such coordinated action can the country hope to thwart the rising tide of cyber threats targeting its essential services.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here