SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Mathias Tausig, information security expert at SBA Research, gave an interesting talk on “The monster in your basement: Security risks of CI/CD systems” at both Continuous Lifecycle / ContainerConf 2024 in Mannheim and BSides Vienna 2024. ... Read More
At the 35th International Conference on Principles of Diagnosis and Resilient Systems (DX’24), an event co-organized by TU Graz and Ben Gurion University, and sponsored by AIJ, Dimitris Simos gave a keynote titled “Combinatorial Methods beyond Testing: Optimizing Disaster Scenarios to Strengthen Disaster Preparedness and Resilience”. In his keynote, Dimitris… Read More
Johanna Ullrich participated in the panel discussion together with Christiane Ahlborn, (Assistant Professor of Public International Law, Trinity College Dublin), Jeanette Gorzala (Legal Expert for the EU AI Act & AI Governance and Member of the Austrian AI Advisory… Read More
On November 13th, Alexander Schatten, senior researcher at SBA Research, gave a very well received keynote on "Will AI save us from the software complexity trap?" at the Continuous Lifecycle / ContainerConf 2024 in Mannheim. ... Read More
Last Saturday, We_0wn_Y0u hosted students from the course “Attacks and Defenses in Computer Security”, which we hold jointly with the Security and Privacy research group at TU Wien at SBA Research to participate in the Bambi CTF, where… Read More
Luiza Corpaci, representing SBA’s CORE and CALGO, joined the 36th International Conference on Testing Software and Systems (ICTSS), held from October 30 to November 1 in London, UK. In the very first session of… Read More
Professor Violet Syrotiuk from Arizona State University visited the MATRIS Research Group for two days of intensive research discussions and exchange from October 24-25, 2024. Prof. Syrotiuk is a distinguished researcher in mathematical system dynamics modeling, wireless networks, and algorithm development. ... Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞