A Fire Truck Burned Down Near Struga: Two Firefighters in Hospital, and the Season Has Barely Started
08.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
07.08.2026
06.08.2026
08.08.2026
08.08.2026
07.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
07.08.2026
06.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
08.08.2026
07.08.2026
09.03.2026
27.02.2026
19.02.2026
08.08.2026
07.08.2026
06.08.2026
23.04.2026
23.04.2026
12.04.2026
Two Polish security researchers decided to check how vulnerable their country's internet is. Not on commission from a ministry, not for money - but, as they put it themselves, out of a feeling that the country they live in should be safer. The result they presented at the Def Con conference in Las Vegas is damning: over 10,000 public institutions and around 250,000 sites with security flaws.
Among them are airports, hospitals and government offices. These are not theoretical weaknesses on some forgotten server, but systems through which people's daily lives pass.
Robert Kruczek and Kamil Szczurowski found critical flaws in the content management system Pad CMS, used widely across the Polish administration. Through it they got into over 300 public sites without needing a password. The vendor did not fix the software - the reason being that it has already been declared obsolete and is no longer maintained.
That is the sentence that stings most. The software is not vulnerable because some attacker was a genius, but because the company that sold it decided it was no longer their obligation, and the institutions that bought it carried on using it as if nothing had happened.
The second flaw gave them access to the sites of around two thirds of the Polish judiciary - approximately 245 courts. The two reported their findings to the state through official channels.
What they describe next is the part anyone who has worked with institutions in the Balkans will recognise instantly. Some of the errors were extremely simple to exploit, but were not taken seriously - several software vendors treated the reports as a nuisance. Not as a problem to be solved, but as something ruining their day.
The additional problem they point to is systemic: Poland has no established programmes for rewarding people who report flaws, nor any clear route for reporting a bug in the first place. So two people who want to help have to work out for themselves who to contact.
All of this is happening while Poland is trying to strengthen its cyber defences after a wave of suspected Russian attacks on its energy and water suppliers. Some of those attacks went through exactly this kind of weak protection. That is the context - a country that knows it is a target, and still has a quarter of a million sites with holes in them.
At the end of their talk, Kruczek and Szczurowski said the gruelling work had been worth it, because thanks to it we are all „a little safer”. The tone is modest. There is another way to read it: it took the effort of two enthusiasts to find out what the institutions could have checked themselves, with budget money, at any time.
The latest 10 news from this category
The model reached the „critical cybersecurity threshold” - it could find a weakness and attack on its own. The assessment...
Not a single accepted or rejected correction in three months, and millions of people are still reading it every month....
Nine million square metres of production space for chips to power robots and orbital data centres. The day before the...
The two biggest dating apps suddenly discover that meeting in person was the point. Bumble's revenue fell 15.2 percent, which...
Jeff Dean, Google's thirtieth employee, is walking out after 27 years and taking three of the company's best researchers with...
Private Relay hides your IP address and is paid for through iCloud+. Two researchers showed it can be bypassed, but...
The rocket company made 7.8 billion in a single quarter, and almost 2 billion of it came from data centres...
Alex Karp argues that companies building language models pipe your expertise into their model to take your business. In the...
Norwegian researchers found code in smart TV apps that turns your home connection into a tunnel for someone else's traffic....
The operator covering 67 million consumers admitted it does not have power for everyone and decided in advance who gets...
This site uses cookies - is that okay? Learn more
Be the first to know when Metla launches something new
Leave your email and we will write when there is a new guide or something new on Metla.