SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Vulnerability Overview Checkmk in versions before 2.4.0p13, 2.3.0p38 and 2.2.0p46, as well as since version 2.1.0b1 is prone to a path traversal vulnerability in the report scheduler. Due to an insufficient validation of a file name input, users can store reports in arbitrary locations on the server. Read More
Tomasz Miksa, senior researcher at SBA Research and TU Vienna, published a paper in ACM Transactions on the Web titled You Shall Not Pass (Without Consent): Enforcing Data Sovereignty with Solid Pods. ... Read More
As part of an IEEE Industry Connection on Synthetic Data our colleague Rudolf Mayer, senior researcher at SBA Research, co-authored a white paper on privacy risks, metrics, and governance in synthetic data. Read More
SBA Research was delighted to welcome Dr. Fatma Nur Esirci Oral as a visiting researcher during September 2025. During her stay, Dr. Esirci Oral delivered valuable seminars for our students and junior researchers and led vital discussions with our institute's members. ... Read More
Our colleagues Michael Koppmann, senior information security consultat at SBA Research, and Mathias Tausig, information security consultant at SBA Research Research gave two insightful talks on ... Read More
Our colleagues Nicolas Petri, Information Security Consultant, and Gerald Sendera, Data Protection Supervisor and Legal Counsel, gave an expert talk on Ich wollte nur Software bauen – und jetzt mach ich CRA-Compliance on September 30 at the LSZ Cyber Crime Forum Graz. ... Read More
Our colleagues Stefan Jakoubi, Director of Professional Services, and Mathias Tausig, Senior Consultant, are giving an expert talk on CRA, ASVS & SAMM – 3 Abkürzungen mit Schlagkraft – MFG on September 18, at the LSZ Cyber Crime Forum Salzburg. ... Read More
Our colleagues Georg Goldenits, and Thomas Neubauer published a new paper on Taxonomy of cybersecurity consideration in agriculture. This paper explores the key cybersecurity threats and reliability risks in Agriculture 4.0 by mapping potential faults and pitfalls to emerging digital technologies in farming. It also discusses countermeasures, legal frameworks,… Read More
From September 19 to 21, around 65 talented and curious women and FINTA* immersed themselves in the exciting world of cybersecurity at the University of Vienna. This continuing education and networking program is unique in Europe and is designed to make it easier to enter and advance in IT security. ... Read More
Combinatorial Testing is a highly effective black-box testing method that combines small test sets with strong fault detection capabilities. However, faced with unknown file formats or network protocols, it requires a method to extract a model of possible parameters and values to use in its test cases. At the 37th… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞