Polish researchers expose thousands of vulnerable public websites

BusinessCyber Security1 hour ago24 Views

Security researchers in Poland have identified widespread vulnerabilities affecting a vast number of the nation’s public agencies and digital services. The investigation was conducted by two experts who sought to assess their country’s exposure to potential cyberattacks, driven by patriotic concerns for national safety.

During a presentation at the Def Con cybersecurity conference held recently in Las Vegas, Robert Kruczek and Kamil Szczurowski revealed that they had discovered over 10,000 affected public entities. Their scan uncovered approximately 250,000 websites containing security flaws. The scope of the risk extends to critical infrastructure including airports, hospitals, government offices, and judicial institutions.

The duo found that many organisations rely on buggy software from vendors who fail to address these issues promptly. A significant factor contributing to this vulnerability is the absence of bug bounty programmes or accessible channels for reporting security flaws. Some vendors have dismissed such reports as mere inconveniences rather than critical threats requiring immediate remediation. This attitude allows easily exploitable bugs to persist, leaving public services open to hijacks and other malicious attacks.

The findings emerge at a time when Poland is actively strengthening its cyber defences following a series of suspected Russian hacks targeting energy and water providers in the region. These previous incidents were often facilitated by weak cybersecurity measures within targeted organisations.

Specifically, Kruczek and Szczurowski identified critical vulnerabilities in Pad CMS, a widely used content management system. This flaw enabled them to access more than 300 public websites without requiring authentication credentials. The software developer had ceased support for the platform as it reached end of life status, yet continued usage by government bodies persisted.

Another discovered bug granted researchers access to roughly two-thirds of Poland’s judiciary network, encompassing approximately 245 courts. Despite these severe risks being reported through various official channels, immediate fixes have not been universally implemented across all affected sectors.

The researchers concluded that their extensive work was ultimately worthwhile for the collective security posture of the nation.

Post Disclaimer

The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.

This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.

The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.

Our Socials

Recent Posts

Stockmark.1T logo with computer monitor icon from Stockmark.it
Loading Next Post...
Popular Now
Loading

Signing-in 3 seconds...

Signing-up 3 seconds...