SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Neuron Automation offers modular and highly efficient automation solutions for the networked industry. They develop customized solutions for customers in industrial sectors such as machine and process automation, logistics, railroad equipment and robotics. A core product is a TÜV-certified development kit that supports engineering projects… Read More
Our MLDM team, in cooperation with Research Institute – Digital Human Rights Center, lead a specialist seminar addressing the pivotal security and legal concerns associated with artificial intelligence (AI). Read More
On February 25th we had our SBA Security Meetup @ Dynatrace in Vienna.
Catherine Easdon gave a talk on Security and Privacy by Design in the SDLC: Why, When, How?. She talked about security and privacy and why they are so important but tricky to get right. Read More
End of February, our colleague Florian Holzbauer, researcher at SBA Research, gave a talk on "From Austria to Ukraine and back: Active measurements to detect Internet outages" at the AT:NOG event in Linz. Read More
Bernhard Garn participated as trainee in the 1st NERO Winter School on Fire Spread and Behavior Reconstruction, which was held between February 18 – 21, 2025, at the Command Center of the Autoridade Nacional de Emergência e Proteção Civil (engl.,Portuguese National Authority for Emergency and Civil Protection;… Read More
We are proud to announce that we have been awarded the 2025 Swift Provider – Customer Security Programme Assessment label by Swift. This prestigious recognition highlights our commitment to maintaining high cybersecurity standards and excellence in customer security assessments. The label was granted following a rigorous… Read More
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. Read More
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page. Read More
The research project combinatorial security testing of the MATRIS Research Group has been nominated in the category Non-University Research for the 2025 Houska Prize! Since its establishment in 2005, the Houska Prize is sponsored… Read More
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. ∞