Image Credits:Filip Radwanski / SOPA Images / LightRocket / Getty Images2:00 PM PDT · August 7, 2026
Two Polish information researchers wanted to find retired however susceptible their country’s net was to imaginable cyberattacks, and rapidly recovered that thousands of nationalist agencies and websites were astatine hazard of being hacked.
At the Def Con cybersecurity league successful Las Vegas connected Friday, information researchers Robert Kruczek and Kamil Szczurowski said they wanted to recognize the authorities of Poland’s nationalist web retired of a consciousness of patriotism and a tendency to marque it safer for everyone.
Before long, the duo discovered much than 10,000 affected nationalist entities with 250,000 websites with information flaws, including airports, hospitals, and authorities offices.
The researchers recovered that immoderate of the vendors’ buggy software, coupled with a deficiency of bug bounties and ways to study information flaws, are putting Poland’s nationalist services astatine hazard of hijacks and different attacks. The researchers besides said that immoderate bugs were incredibly casual to exploit but were not ever taken seriously, with immoderate vendors describing the bug reports arsenic inconveniences.
The probe comes arsenic Poland is trying to enactment up its cyber defenses aft a question of suspected Russian hacks targeting the country’s energy and water providers. Some of the hacks person been carried retired by taking advantage of anemic cybersecurity.
Kruczek and Szczurowski recovered respective bugs successful the wide utilized contented absorption strategy Pad CMS, which website owners usage to signifier and show content.
The 2 recovered captious vulnerabilities successful one web strategy called Pad CMS, which allowed them to easy entree implicit 300 nationalist websites without needing a password. The bundle developer did not spot the bundle due to the fact that it had go “end of life” and was nary longer supported.
Another bug allowed them to summation entree to the websites of immoderate two-thirds of Poland’s judiciary, oregon astir 245 courts, they said.
The duo reported their findings to the authorities done assorted authoritative channels.
The researchers said during their speech that it was yet worthy the hassle, saying that arsenic a effect we are “a small spot much safe.”
When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.
Zack Whittaker is the information exertion astatine TechCrunch. He besides authors the play cybersecurity newsletter, this week successful security.
He tin beryllium reached via encrypted connection astatine zackwhittaker.1337 connected Signal. You tin besides interaction him by email, oregon to verify outreach, astatine zack.whittaker@techcrunch.com.















English (US) ·