Security researchers scanned the Polish web and found courts, hospitals, and airports at risk of hacks
Researchers found common points of failure, like software used to organize and display web content, could have allowed hackers to run riot through government websites.
Two Polish security researchers set out to assess the susceptibility of their nation's internet infrastructure to cyberattacks, revealing a concerning discovery. At the Def Con cybersecurity conference in Las Vegas, Robert Kruczek and Kamil Szczurowski disclosed that over 10,000 public agencies and 250,000 websites across Poland were exposed to security vulnerabilities.
Among the targeted entities, airports, hospitals, and government offices were among those at risk. The researchers attributed the susceptibility to faulty software and the absence of bug bounties, which made it difficult for security flaws to be reported and addressed. Notably, they found critical vulnerabilities in widely-used content management system Pad CMS, which allowed them to access over 300 websites without passwords due to the software being "end of life" - no longer supported.
The researchers reported their findings to governmental authorities, hoping to enhance Poland's cyber defenses following a series of suspected Russian hacks targeting critical sectors like energy and water.
Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.