SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Our colleague Sebastian Raubitzek, researcher at SBA Research and a member of the Security and Privacy Research Group at the University of Vienna, has published a journal article titled Classification of Obfuscation Techniques in LLVM IR: Machine Learning on Vector Representations in MDPI's journal Machine Learning and Knowledge Extraction. ... Read More
SBA Research was proud to participate in the Ekoparty Security Conference 2025, held from October 22-24 in Buenos Aires, Argentina. This year, Max Günther and Philipp Frenzel represented SBA Research and the Security and Privacy Research Group at the University of Vienna… Read More
End of October, we had our SBA Security Meetup on From OWASP to App Secrets Learned with to insightful talks from Fabian Funder (SBA Research) and David Schmidt (Universität Wien). ... Read More
End of October, Florian Holzbauer, researcher at SBA Research and a member of the Security and Privacy Research Group at the University of Vienna, presented his paper Tracking Internet Disruptions in Ukraine: Insights from Three Years of Active Full Block Scans at the ACM Internet Measurement Conference in Madison, Wisconsin,… Read More
Checkmk in versions before 2.4.0p14 and 2.3.0p39, as well as in branches 2.2.0, 2.1.0 and 2.0.0 is prone to a Stored Cross-Site Scripting (XSS) vulnerability when used in a distributed monitoring setup. Any connected remote site can inject JavaScript code in the central site's user interface. ... Read More
On October 22 2025, the Diversity Think Tank team hosted the re:think diversity congress at the Vienna Chamber of Commerce. Like last year, Jeanine Lefèvre, Head of Office of Equal Opportunities and research coordinator, and Gregor Roschitz,… Read More
In mid-October, our yearly partner and friends of SBA Research event IMPACT brought together experts, practitioners, and decision-makers from research, industry, and the open-source community. One afternoon with discussion about the latest developments in security, open source, and research and to celebrate our long-standing relationships. This year’s program… Read More
We are proud to announce that we joined the Linux Foundation Europe, further strengthening our role within the international open-source community. With this step, we are reinforcing our commitment to advancing security and resilience in digital infrastructures. ... Read More
David Schmidt, PhD student at CD-Lab AsTra, Sebastian Schrittwieser, key researcher at SBA Research and head of the CD-Lab, and Edgar Weippl, scientific director at SBA Research and full professor for security & privacy at the University of Vienna, received the Distinguished Paper Award at ACM CCS 2025 (A*-rated) for their work Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS Apps. ... Read More
Vulnerability Overview The `win_license` plugin as included in Checkmk agent for Windows versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b2 and 2.0.0p28 allows low privileged users to escalate privileges to Local System due to insecure use of a temporary folder. Recommended… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞