Polish government websites vulnerable to hacking due to common software flaws
Security researchers conducted a scan of Polish web infrastructure and discovered that courts, hospitals, and airports were exposed to potential hacks. The vulnerabilities stemmed from common software used to organize and display web content, which could have allowed attackers to compromise government sites. The findings highlight widespread security weaknesses in critical public services.
The researchers presented their findings at the Def Con conference, driven by patriotic motives to bolster national digital defenses. Their scan revealed over 250,000 vulnerable sites across more than 10,000 public entities, including critical infrastructure like airports and medical facilities.
Specific exploits included a flaw in the discontinued Pad CMS, which enabled password-free access to hundreds of government pages. Another vulnerability compromised roughly two-thirds of the nation's courts. The researchers noted that some software vendors dismissed these security reports as mere inconveniences, hindering remediation efforts.
The exposure of critical public services could significantly disrupt daily life if exploited. Citizens relying on courts, hospitals, or airports may face service outages, data breaches, or compromised personal information. While the researchers reported the flaws, the lack of vendor responsiveness suggests systemic risks that could persist. This situation may also strain Poland's ongoing efforts to counter state-sponsored cyber threats, potentially undermining public trust in digital government services.