SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Since April 9, SBA Research performs a daily scan of all Austrian IP addresses (approximately 12 million) due to the acute threat situation. Thereby, 121,420 IP addresses have been identified that respond to an HTTPS request for a webpage. Each server can be home to one or multiple sites. Of… Read More
Ein Team von SBA Sicherheitsforschern analysiert derzeit detailliert und umfassend für verschiedene Zielgruppen (Administratoren, User etc.) die Bedrohungslage und Konsequenzen, die von der als Heartbleed am 7. April bekanntgewordenen Schwachstelle ausgehen. Nach unserer Einschätzung sind diese wesentlich ernster, als bisher medial kommuniziert wurde. Details dazu werden von uns laufend… Read More
SBA Research ist auch dieses Jahr wieder am Security Forum 2014, der jährlichen IKT-Sicherheitskonferenz des Hagenberger Kreis, mit einem Messestand sowie einem Vortrag am ersten Konferenztag vertreten. Dimitris Simos spricht am ersten Konferenztag, dem 09.04.2014 von 10.10 Uhr – 11.00 Uhr, über “The Mathematics behind an Automated Penetration Testing Framework”. Weitere Infos… Read More
In the general meeting on 7 May 2013, Markus Klemen, CEO of SBA Research, was elected Vice President (Institutional Members) of the Austrian Computer Society. Furthermore, Prof. Stefanie Rinderle-Ma and KommR Hans-Jürgen Pollirer were elected resp. confirmed as Vice Presidents. More information about the Austrian Computer Society can be found… Read More
Unsere Social Snapshot Framework wurde in der Wintersemesterausgabe 2012 von DURST (Studentemagazin des Falters) vorgestellt. Der Artikel ist in der Online Ausgabe von DURST verfügbar, zum Artikel (“Was darf deine App von dir wissen?” Seite 9).
An interview concerning social network security. Ö1 aired the interview in their daily journals on June 8th 2012. Listen to the interview here: OE1_Journal120608_Huber
Markus Huber participated in a panel discussion on data-mining (more). The event was organized by TCC10 as their annual key-event. The event was also featured on IT-Press.
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞