A nationwide security sweep of Poland's public internet infrastructure has exposed a startling reality: thousands of government agencies, hospitals, and airports are running vulnerable software that could be hijacked with minimal effort. The findings, presented at the Def Con cybersecurity conference in Las Vegas, paint a troubling picture of digital neglect in a country already under siege from suspected Russian cyberattacks. Main Developments Security researchers Robert Kruczek and Kamil Szczurowski identified more than 10,000 public entities running 250,000 websites with security flaws. Their scan covered critical infrastructure including airports, hospitals, and government offices, revealing weaknesses that could allow attackers to seize control of these digital services. Read also: Why Cloudflare's AI browser could redefine web automation One particularly alarming discovery involved Pad CMS, a widely used content management system. The researchers found critical vulnerabilities that let them access over 300 public websites without any password. The software vendor had abandoned the product, declaring it end-of-life and refusing to issue patches, leaving these sites permanently exposed. The investigation also uncovered a separate bug that compromised roughly two-thirds of Poland's judiciary, granting access to approximately 245 courts. These are not theoretical risks; the researchers demonstrated real, exploitable pathways into systems that handle sensitive legal and administrative data. The duo reported their findings through official government channels, hoping to trigger remediation. Despite the bureaucratic friction, they maintained that the effort was worthwhile, noting that as a result of their work, the country is now somewhat safer than before. Background Poland has been actively fortifying its cyber defenses following a wave of suspected Russian hacks aimed at the nation's energy and water providers. Many of those intrusions succeeded by capitalizing on weak cybersecurity practices, making the newly discovered flaws particularly concerning given the current threat landscape. The researchers said their motivation was patriotic, driven by a desire to understand the true state of Poland's public web and make it safer for everyone. Their scan was a self-appointed civic audit, filling a gap left by the absence of formal oversight mechanisms. Part of the problem, they noted, is structural. The lack of bug bounty programs and clear channels for reporting security flaws means that even well-intentioned discoveries often go unaddressed. Some vendors dismissed the vulnerability reports as mere inconveniences, refusing to take them seriously. Why It Matters The findings expose a systemic weakness in how public institutions procure and maintain software. When vendors abandon products without transition plans, or when agencies fail to upgrade, they create permanent backdoors into critical services that citizens depend on daily. For a country actively defending against state-sponsored cyberattacks, these vulnerabilities represent low-hanging fruit for adversaries. An attacker exploiting the Pad CMS flaw could potentially disrupt court operations, compromise hospital systems, or interfere with airport logistics, all with minimal technical skill required. The research also highlights a broader governance issue: without mandatory reporting mechanisms or incentives for responsible disclosure, security gaps can persist silently for years. The public remains unaware of risks until a researcher with civic motivation decides to look. What's Next The researchers have submitted their findings to the Polish government through official channels, but the timeline for remediation remains unclear. The affected agencies will need to migrate away from unsupported software like Pad CMS and patch the judicial system vulnerability to close the most critical exposures. Whether the government will establish formal bug bounty programs or create structured reporting pathways in response to this audit is an open question. The researchers' presentation at Def Con may pressure officials to act, but without systemic changes, similar vulnerabilities could emerge as agencies adopt new technologies without proper security vetting.