
Two security researchers walked into Def Con with a simple question: how bad is Poland’s public internet, really? The answer was worse than most people would want to admit. According to TechCrunch, researchers Robert Kruczek and Kamil Szczurowski identified over 10,000 affected public entities and 250,000 websites with security flaws, covering airports, hospitals, courts, and government offices across the country.
The researchers were motivated by patriotism, they said, and a genuine desire to make Poland’s digital infrastructure safer. But what they found points to a systemic problem that goes well beyond one country’s government IT habits. Buggy vendor software, no bug bounty programs, and almost no formal channels for reporting security flaws left critical public services exposed.
One of the most alarming findings involved Pad CMS, a content management system widely used across Polish public sector websites. Kruczek and Szczurowski found a critical vulnerability in the software that let them access over 300 public websites without a password. The software developer’s response? The product had reached end-of-life status, so no patch was coming. That’s the kind of answer that should concern anyone who thinks public institutions have baseline accountability for protecting user data.
The court system fared no better. A separate bug gave the researchers access to the websites of roughly two-thirds of Poland’s judiciary, around 245 courts. When they reported some of these issues through official channels, certain vendors reportedly described the bug reports as inconveniences. Not urgent. Not a priority. An inconvenience.
This research lands at a particularly uncomfortable moment. Poland has been dealing with a wave of suspected Russian cyberattacks targeting energy and water infrastructure, and weak cybersecurity has been a known entry point in several of those incidents. Finding that hospitals and airports are running on unpatched, unsupported software is not just embarrassing. It’s a concrete risk to public safety and to the personal data of millions of people who have no choice but to interact with these systems.
The broader pattern here is familiar. Public sector organizations often run outdated software because procurement cycles are slow and IT budgets are thin. Vendors discontinue support without meaningful transition plans. And nobody builds in a clear, trusted way to report vulnerabilities when they are found. The result is exactly what Kruczek and Szczurowski documented: a public web that is large, widely trusted, and quietly falling apart at the seams.
The duo said they reported everything through official government channels. And they closed their Def Con talk on a cautiously optimistic note, saying Poland is now “a little bit more safe.” That framing is honest. A little bit. After scanning a quarter million websites and finding critical holes in courts, hospitals, and airports, a little bit is the realistic outcome when the structural problems stay in place.