SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
We are proud to announce that we joined the Linux Foundation Europe, further strengthening our role within the international open-source community. With this step, we are reinforcing our commitment to advancing security and resilience in digital infrastructures. ... Read More
David Schmidt, PhD student at CD-Lab AsTra, Sebastian Schrittwieser, key researcher at SBA Research and head of the CD-Lab, and Edgar Weippl, scientific director at SBA Research and full professor for security & privacy at the University of Vienna, received the Distinguished Paper Award at ACM CCS 2025 (A*-rated) for their work Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS Apps. ... Read More
Vulnerability Overview The `win_license` plugin as included in Checkmk agent for Windows versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b2 and 2.0.0p28 allows low privileged users to escalate privileges to Local System due to insecure use of a temporary folder. Recommended… Read More
Vulnerability Overview Checkmk in versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b1 is prone to a path traversal vulnerability in the report scheduler. Due to an insufficient validation of a file name input, users can store reports in arbitrary locations on the server. Read More
Tomasz Miksa, senior researcher at SBA Research and TU Vienna, published a paper in ACM Transactions on the Web titled You Shall Not Pass (Without Consent): Enforcing Data Sovereignty with Solid Pods. ... Read More
As part of an IEEE Industry Connection on Synthetic Data our colleague Rudolf Mayer, senior researcher at SBA Research, co-authored a white paper on privacy risks, metrics, and governance in synthetic data. Read More
SBA Research was delighted to welcome Dr. Fatma Nur Esirci Oral as a visiting researcher during September 2025. During her stay, Dr. Esirci Oral delivered valuable seminars for our students and junior researchers and led vital discussions with our institute's members. ... Read More
Our colleagues Michael Koppmann, senior information security consultat at SBA Research, and Mathias Tausig, information security consultant at SBA Research Research gave two insightful talks on ... Read More
Our colleagues Nicolas Petri, Information Security Consultant, and Gerald Sendera, Data Protection Supervisor and Legal Counsel, gave an expert talk on Ich wollte nur Software bauen – und jetzt mach ich CRA-Compliance on September 30 at the LSZ Cyber Crime Forum Graz. ... Read More
Our colleagues Stefan Jakoubi, Director of Professional Services, and Mathias Tausig, Senior Consultant, are giving an expert talk on CRA, ASVS & SAMM – 3 Abkürzungen mit Schlagkraft – MFG on September 18, at the LSZ Cyber Crime Forum Salzburg. ... Read More
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. ∞