Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked.
At the Def Con cybersecurity conference in Las Vegas on Friday, security researchers Robert Kruczek and Kamil Szczurowski said they wanted to understand the state of Poland’s public web out of a sense of patriotism and a desire to make it safer for everyone.
Before long, the duo discovered more than 10,000 affected public entities with 250,000 websites with security flaws, including airports, hospitals, and government offices.
The researchers found that some of the vendors’ buggy software, coupled with a lack of bug bounties and ways to report security flaws, are putting Poland’s public services at risk of hijacks and other attacks. The researchers also said that some bugs were incredibly easy to exploit but were not always taken seriously, with some vendors describing the bug reports as inconveniences.
The research comes as Poland is trying to shore up its cyber defenses after a wave of suspected Russian hacks targeting the country’s energy and water providers. Some of the hacks have been carried out by taking advantage of weak cybersecurity.
Kruczek and Szczurowski found critical vulnerabilities in the widely used content management system Pad CMS, which allowed them to easily access over 300 public websites without needing a password. The software developer did not patch the software because it had become “end of life” and was no longer supported.
Another bug allowed them to gain access to the websites of some two-thirds of Poland’s judiciary, or about 245 courts, they said.
The duo reported their findings to the government through various official channels.
The researchers said during their talk that it was ultimately worth the hassle, saying that as a result we are “a little bit more safe.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.
Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you.Save up to $300 today!
ChatGPT brings unlimited text chats to free users
Amid legal battles, Suno says it will start watermarking songs
Ford’s new electric truck, ‘Fathom,’ starts at $28,350
Influencers draw backlash for attending OpenAI’s first luxury trip
Sequoia’s Shaun Maguire leads $1B round for nuclear startup Valar Atomics
YouTuber Hank Green says his AI usage is ‘not healthy’






