Researchers claim that tens of thousands of public institution websites in Poland have vulnerabilities
Ai Focus
Polish researchers claim that tens of thousands of local public institutions and approximately 250,000 websites are affected by security vulnerabilities, including courts, hospitals, and airports.
两名波兰安全研究人员在拉斯维加斯举行的 Def Con 网络安全大会上表示,他们对本国公共网络进行排查后,发现大量政府和公共服务网站存在可被利用的安全缺陷,波及法院、医院、机场和政府办公室等机构。
涉及上万家公共机构
研究人员 Robert Kruczek 和 Kamil Szczurowski 称,他们共发现超过 1 万家受影响的公共实体,相关问题涉及约 25 万个网站。两人表示,排查的出发点是了解波兰公共网络的真实安全状况,并推动相关系统修复。
他们提到,部分问题来自供应商软件本身存在缺陷,另一部分则与漏洞上报渠道不足有关。一些机构和厂商既没有漏洞奖励计划,也缺少清晰的报告入口,导致问题长期暴露在外。
部分漏洞可直接接管网站
两人称,他们在波兰较常用的内容管理系统 Pad CMS 中发现了多项漏洞。其中一个高危问题可让攻击者在无需密码的情况下进入 300 多个公共网站。
研究人员表示,这套软件因已停止支持而没有获得补丁更新。另一个漏洞则影响更广,按他们的说法,攻击者可借此进入波兰约三分之二的司法系统网站,涉及大约 245 家法院。
- 受影响公共实体:超过 1 万家
- 涉及网站数量:约 25 万个
- 可无密码访问的网站:超过 300 个
波兰正加强网络防御
这项研究发布之际,波兰正加强网络防御。此前,波兰能源和供水系统曾遭遇一系列疑似与俄罗斯有关的网络攻击,部分事件被认为与基础安全薄弱有关。
研究人员表示,他们已通过多个官方渠道向政府报告相关发现。两人在演讲中称,整个过程虽然繁琐,但至少让相关系统的风险被更早暴露,也让公共网络环境变得更安全一些。
Follow HQYC official accounts to stay updated
Views 17
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。

No comments yet. Be the first!