Recent AI cybersecurity tests exposed weaknesses in both frontier models and the environments built to contain them.
Two Polish security researchers found thousands of public agencies and 250,000 websites with security flaws, including courts, hospitals, airports and government offices.
Two Polish security researchers, Robert Kruczek and Kamil Szczurowski, scanned Poland’s public web to assess how vulnerable it was to cyberattacks. They found more than 10,000 affected public entities and 250,000 websites with security flaws, including airports, hospitals and government offices.
The researchers discussed the findings at the Def Con cybersecurity conference in Las Vegas. Their stated motivation was to make Poland’s internet safer for everyone.
The findings point to common points of failure in software used to organize and display web content. According to the report, buggy vendor software, limited bug bounty programs and unclear ways to report vulnerabilities left public services exposed to hijacks and other attacks.
For public agencies, the takeaway is straightforward: unsupported software, weak reporting channels and slow vendor response can turn routine web tools into systemic security risks. Security teams should prioritize inventorying public-facing software and ensuring there is a clear process for receiving and acting on vulnerability reports.
Kruczek and Szczurowski found critical vulnerabilities in the widely used content management system Pad CMS. Those flaws allowed access to more than 300 public websites without needing a password, but the software developer did not patch the system because it had reached end of life and was no longer supported.
Another bug allowed the researchers to gain access to websites for about two-thirds of Poland’s judiciary, or around 245 courts. The details underscore why public bodies should treat end-of-life software as an urgent operational risk, not a routine maintenance issue.
The research comes as Poland is working to strengthen its cyber defenses after suspected Russian hacks targeting energy and water providers. TechCrunch reported that some of those hacks took advantage of weak cybersecurity.
The researchers said they reported their findings to the government through official channels. Their closing assessment was that the effort was worth the hassle because the result made people “a little bit more safe.”
Recent AI cybersecurity tests exposed weaknesses in both frontier models and the environments built to contain them.

Google’s new hacker naming system is meant to make cyber threat tracking easier to follow and act on.

Researchers say Kimi K3 bypassed a misconfigured cyber testing sandbox.

Astra testing triggered OpenAI’s first potential “Critical” cybersecurity risk flag.