At Def Con, Polish researchers Robert Kruczek and Kamil Szczurowski revealed a nationwide scan that exposed major security gaps across public services. They found more than 10,000 affected public entities and roughly 250,000 vulnerable websites, including airports, hospitals and government sites. Critical Pad CMS flaws allowed access to 300+ sites without a password, and about 245 courts were reachable. The researchers reported the issues to authorities to help improve national cyber defenses.
Nationwide Scan Finds 250,000 Vulnerable Websites in Poland — Airports, Hospitals and Courts Exposed

Two Polish security researchers have revealed the results of a large-scale scan of their country's public web infrastructure, finding widespread vulnerabilities that put critical services at risk.
Key Findings
Speaking at the Def Con cybersecurity conference in Las Vegas, Robert Kruczek and Kamil Szczurowski said their scan identified more than 10,000 affected public entities and roughly 250,000 websites with security flaws. The affected sites include airports, hospitals, government offices and court systems.
The researchers discovered critical vulnerabilities in the widely used content management system Pad CMS, which allowed access to over 300 public websites without supplying a password. The Pad CMS vendor did not patch the flaw because the product had reached "end of life" and was no longer supported.
Another serious vulnerability enabled the researchers to access approximately 245 courts — about two-thirds of Poland's judiciary — raising alarms about the integrity and confidentiality of legal records and case-management systems.
Causes and Risk Factors
Kruczek and Szczurowski highlighted several root causes: buggy or unsupported third-party software, the absence of formal bug-bounty programs, and a lack of straightforward reporting channels for security issues. They also reported that some vendors downplayed or dismissed vulnerability reports as mere inconveniences instead of addressing security flaws promptly.
Context and Response
The findings come as Poland works to strengthen its cyber defenses following a series of suspected Russian intrusions that targeted energy and water providers — incidents in some cases enabled by weak cybersecurity. The researchers said they reported their discoveries to government authorities via multiple official channels.
"Despite the hassle of reporting and coordinating fixes, the work makes Poland a little bit more safe," the pair told the Def Con audience.
Implications: The scan underscores how unsupported software, limited reporting mechanisms, and vendor complacency can rapidly translate into national security and public-safety risks. It also demonstrates the value of proactive, ethical research and clear disclosure pathways to reduce attack surfaces across public services.
Help us improve.



























