Two Polish security researchers wanted to find out how vulnerable their country’s internet was to potential cyberattacks and quickly found that thousands of public agencies and websites were at risk of being hacked. Before long, the duo discovered more than 10,000 affected public entities with 250,000 websites with security flaws, including airports, hospitals, and government offices. Kruczek and Szczurowski found critical vulnerabilities in the widely used content management system Pad CMS, which allowed them to easily access over 300 public websites without needing a password. The software developer did not patch the software because it had become “end of life” and was no longer supported. Another bug allowed them to gain access to the websites of some two-thirds of Poland’s judiciary, or about 245 courts, they said.