Judiciary-wide compromise — another bug allowed the researchers to gain access to websites covering about two-thirds of Poland's judiciary, or approximately 245 courts .
Widespread easy-to-exploit bugs — some flaws were described as "incredibly easy to exploit" but were not treated seriously by vendors, who dismissed the bug reports as mere "inconveniences" .
Kruczek and Szczurowski pointed to three interrelated failures that enabled these risks:
End-of-life, unsupported software — Pad CMS and other unpatched platforms continued to run across critical public services even after vendor support ended .
No bug bounty or structured reporting channels — the lack of official bug bounty programs and secure ways to report security flaws meant researchers and ethical hackers had no clear path to disclose issues .
Dismissed bug reports — when researchers did report findings directly to vendors, their reports were frequently disregarded or described as minor inconveniences rather than critical security risks .
This research was presented against a backdrop of escalating suspected Russian state-sponsored cyberattacks on Poland's critical infrastructure. The patterns Kruczek and Szczurowski found in public web infrastructure are the same weaknesses being actively weaponized:
Coordinated attacks targeted Poland's energy infrastructure, including 30 wind and solar power installations and a large combined heat and power (CHP) plant. These were attributed to the Russian state-backed Sandworm APT group and involved wiper malware. This was the first cyberattack on Poland's energy sector with a purely destructive objective .
A parallel, previously undisclosed attack hit a smaller CHP plant serving 50,000 residents. Attackers used a novel private APN pivot technique (the first documented use of this vector in a real-world attack), accessed a WAGO PLC protected only by default admin credentials, and shut down a steam turbine and water treatment system. They then sabotaged network devices and destroyed logs to hinder recovery .
Hackers breached at least five Polish water treatment plants in 2025, gaining access to industrial control systems (ICS) that regulate pumps, filters, and chemical dosing. Attackers altered operational parameters and circulated recordings on social media .
The attack vector, in every case, was unremarkable: default passwords and control systems connected directly to the internet . Poland's Internal Security Agency (ABW) formally charged two Russian nationals for a campaign of 17 cyberattacks targeting critical infrastructure, including seven water and wastewater treatment plants
.
Kruczek and Szczurowski's findings demonstrate that the same pattern of weak security — end-of-life software, no reporting mechanisms, and dismissed bug reports — that left Poland's public web infrastructure exposed also mirrors the vulnerabilities being actively exploited in suspected Russian attacks on Poland's energy and water sectors. Weak default credentials, unpatched systems, and unsegmented networks were direct attack vectors in both the web infrastructure flaws and the destructive OT-level attacks on power plants and water treatment facilities.