SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Today we attend the highly prestigious International Conference on Business Process Management (BPM’2009) and present our paper “Business Process-based Resource Importance Determination” in the main track.
Our paper “A Reference Model for Risk-Aware Business Process Management” has been accepted at the 4th International Conference on Risks and Security of Internet and Systems (CRISIS2009).
Our paper “Towards Automating Social Engineering Using Social Networking Sites” has been accepted at the International Conference on Privacy, Security, Risk and Trust (PASSAT2009).
From 18th to 19th June 2009 Aad van Moorsel and Simon E. Parkin from Newcastle University will visit our research center. Our goal is to identify and initialize joint research projects between Newcastle University and Secure Business Austria in the field of economically justified security solutions. On 18th June… Read More
Edgar Weippl gives a talk on Database Forensic at the Security Forum in Hagenberg. Abstract: Whenever data is being processed, there are many places where parts of the data are temporarily stored; thus forensic analysis can reveal past activities, create a (partial) timeline and restore deleted data. While this fact… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞