SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. Read More
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. Read More
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation (CVE-2026-16971) and user authentication (CVE-2026-18362) against brute-force attacks. Read More
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time. Read More
The latest issue of the OCG Journal 02/26, dedicated to “Sustainability and Computer Science – The Potential of AI for Ecology and Climate,” highlights how digital technologies can contribute to a more sustainable future. Our researchers and experts contributed to this discussion by exploring the opportunities and challenges of artificial intelligence in different domains. Read More
At the end of June, forty-seven female HTL students from across Austria participated in the two-day Code. Protect. Empower. – Cyber Security for Female Students workshop, gaining practical, hands-on experience in cybersecurity while exploring education and career opportunities in the field. Read More
Our colleague Walid Fdhila, senior researcher and team lead at SBA Research and senior researcher at the University of Vienna at the Faculty of Computer Science, gave a talk titled Trustworthy Decentralized Digital Ecosystems, during his stay as guest professor at the Faculty of Sciences and Techniques, Université de Tours, France. Read More
We congratulate our key researcher Maria Christakis, and Head of the Research Unit Software Engineering at TU Wien Informatics, on receiving a prestigious European Research Council (ERC) Proof of Concept Grant for her project CIRCUZZ. Read More
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role. This exposure allows potential unauthorized access to network devices. Read More
SBA Research was proud to support OWASP Global AppSec EU 2026, one of Europe's leading conferences on application security, held from June 22–26, 2026, at the Austria Center Vienna.. The event brought together security researchers, practitioners, and industry experts to exchange knowledge, discuss emerging threats, and explore the latest developments in application security. Read More
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. ∞