Floragasse 7 – 5th floor, 1040 Vienna
Subscribe to our Newsletter

SBA Research is a research center for Information Security
funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.

Recent News:

SBA Security Advisory – Cyberduck and Mountain Duck – Improper Certificate Store Handling (CVE-2025-41255)

Cyberduck and Mountain Duck improper handle TLS certificate pinning for untrusted certificates (e.g., self-signed), unnecessary installing it to the Windows Certificate Store of the current user without any restrictions. This potentially allows attackers to bypass certificate-based authentication or authorization of other programs that trust this certificate store. ... Read More
Logo SBA Security Advisories

AI5Production – Test Before Invest Project with Spusu

Spusu is an Austrian mobile network operator and operates as a mobile virtual network operator (MVNO) using the Drei network. Spusu offers premium-quality mobile plans at affordable prices. Since 2021, Spusu has also been fulfilling its role as a technology leader by expanding regional… Read More
project logo

SBA @ Conference on Excellent research requires the right framework

In mid-May, Jeanine Lefèvre, head of Office of Equal Opportunities at SBA Research, attended the important Viennese conference on Excellent research requires the right framework which set the tone for non-discriminatory research. Around 80 experts in science, politics, and gender equality came together to discuss strategies for… Read More
SBA @ Conference on Excellent research requires the right framework

SBA @ Security Forum Hagenberg

In mid-May, our colleague Reinhard Kugler, applied research consultant at SBA Research, gave a talk on Tracing the Invisible: how to create Observability on Edge Devices with eBPF. His presentation focused on tracing protocols in embedded systems by instrumenting the kernel. He discussed protocols such as SPI, I2C, and… Read More
Reinhard Kugler presenting

AI5Production – Test Before Invest Project with Infraprotect

For over 25 years, Infraprotect has supported companies in the fields of crisis, emergency, risk, and security management, as well as crisis communication and R&D. The company provides tailored crisis management solutions to clients from a variety of sectors, including manufacturing, critical infrastructure, and public services. Read More
project logo