Two Polish security researchers scanned their nation’s internet, revealing that over 10,000 public entities and 250,000 websites were at cybersecurity risk. Among these were airports, hospitals, and government offices. The duo discovered critical flaws in the widely used content management system Pad CMS, allowing them access to more than 300 public sites without needing a password.
The researchers also highlighted that some vendors had buggy software and lacked bug bounty programs or mechanisms for reporting security issues, putting these public services at risk of hijackings. Some bugs were so easy to exploit that they weren’t always taken seriously by the vendors who dismissed them as inconveniences.
Poland’s efforts to strengthen its cyber defences come after a series of suspected Russian hacks targeting energy and water providers. The research adds urgency, especially given that one system allowed access to about 245 courts out of Poland’s two-thirds judiciary.
The findings were reported to the Polish government via official channels, but the researchers say it was worth the effort. After all, a little extra safety is never a bad thing.







