Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Two Researchers Found 250,000 Vulnerable Polish Government Websites. Nobody Made Them Do It.

Two guys with laptops found what the Polish government apparently didn't: its own public web infrastructure was riddled with holes.
Security researchers Robert Kruczek and Kamil Szczurowski presented their findings at the Def Con cybersecurity conference in Las Vegas, according to TechCrunch. They scanned Poland's public-facing internet on their own time, driven by what they described as patriotism, and found more than 10,000 affected public entities running roughly 250,000 vulnerable websites.
The list includes airports, hospitals, and government offices, per TechCrunch. Critical infrastructure was sitting exposed.
The Court System Was Wide Open
One of the worst findings involved a content management system called Pad CMS, widely used across Polish public websites. Kruczek and Szczurowski found critical vulnerabilities that let them access over 300 public websites without needing a password, according to TechCrunch.
The software vendor never patched it. Why? Because the product had reached end-of-life and was no longer supported, TechCrunch reported. Nobody was minding the store.
Another bug gave the researchers access to roughly two-thirds of Poland's judiciary, about 245 courts, according to TechCrunch. Case records, filings, schedules, and potentially sensitive legal documents tied to real people's lives were all reachable because of software nobody bothered to maintain.
Vendors Treated Bug Reports as a Nuisance
According to TechCrunch, some of the bugs the researchers found were incredibly easy to exploit, but vendors didn't take them seriously. Some vendors reportedly described the bug reports as inconveniences.
An inconvenience. That's the word used to describe a hole that could let a hacker into a hospital's systems or a courthouse's records.
Part of the problem, according to TechCrunch, is structural: there's a lack of bug bounty programs and clear channels for reporting security flaws across Poland's public sector. When there's no formal system rewarding people for finding and reporting vulnerabilities, and no clear pipeline for those reports to reach someone who'll act on them, flaws sit there. Sometimes for years.
The Russia Angle Isn't Speculation, It's Recent History
This research didn't happen in a vacuum. Poland has been dealing with a wave of suspected Russian hacking attempts targeting its energy and water providers, according to TechCrunch, and some of those attacks succeeded by exploiting weak cybersecurity.
That's the strongest case for taking this Def Con presentation seriously rather than treating it as a curiosity. Poland sits on NATO's eastern flank, actively supporting Ukraine, and is a demonstrated target for state-linked cyber operations. A government website running unsupported software isn't just sloppy IT management in that context. It's a door left unlocked in a neighborhood with a documented break-in problem.
A Fair Question: Is This Really as Bad as It Sounds?
A reasonable skeptic might push back here. Finding a vulnerability isn't the same as proving it was ever exploited by a malicious actor. TechCrunch's reporting doesn't claim Russian hackers or anyone else actually breached these 300 Pad CMS sites or the 245 courts before the researchers reported them. No breach has been confirmed. No data theft has been documented in connection with these specific findings.
It's also true that white-hat research like this is exactly the system working as intended in one sense: independent researchers found the holes and reported them through official government channels before bad actors could, according to TechCrunch. Kruczek and Szczurowski said the effort was worth it, telling their Def Con audience that as a result, Poland is a little bit more safe.
A government shouldn't need two volunteers with a scanner and a sense of civic duty to find out its court system is running unpatched, unsupported software. That's a job for the agencies responsible for the infrastructure in the first place, and TechCrunch's reporting doesn't indicate any Polish government official has taken public responsibility for the years of neglect that made these findings possible.
What Happens Next
Kruczek and Szczurowski reported their findings to the Polish government through official channels, according to TechCrunch. What isn't clear yet is which of the 250,000 flagged websites have actually been patched, whether the vendor behind Pad CMS or its replacement has issued any fix, and whether Poland plans to establish the bug bounty programs and reporting infrastructure the researchers say are missing.
Those are the questions that matter now. A conference talk raised the alarm. Whether Warsaw treats it as more than an inconvenience is the part nobody can answer yet.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.