Polish Researchers Find 250K Vulnerable Public Websites at Def Con

Original: Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks

Why This Matters

The findings expose systemic cybersecurity gaps in critical public infrastructure across an EU and NATO member state.

Polish security researchers Robert Kruczek and Kamil Szczurowski revealed at Def Con 2026 in Las Vegas that over 10,000 public entities and 250,000 websites in Poland—including airports, hospitals, and courts—contain exploitable security flaws.

At the Def Con cybersecurity conference in Las Vegas on August 7, 2026, Polish researchers Robert Kruczek and Kamil Szczurowski presented findings from a broad scan of Poland's public-facing internet infrastructure. The duo discovered more than 10,000 affected public entities across 250,000 websites with security vulnerabilities spanning airports, hospitals, and government offices.

Among the critical findings: a flaw in the widely-used content management system Pad CMS allowed unauthenticated access to over 300 public websites. The software developer declined to issue a patch, citing the product's end-of-life status. A separate vulnerability granted access to websites belonging to approximately two-thirds of Poland's judiciary—roughly 245 courts.

The researchers noted that some vendors treated bug reports as mere 'inconveniences' rather than urgent security matters, and that a lack of bug bounty programs and formal vulnerability disclosure channels exacerbated the risk. The research coincides with a wave of suspected Russian cyberattacks targeting Poland's energy and water infrastructure. Kruczek and Szczurowski reported their findings through official government channels, concluding their talk by saying the effort made Poland 'a little bit more safe.'

Source

techcrunch.com — Read original →