SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
At the end of June, forty-seven female HTL students from across Austria participated in the two-day Code. Protect. Empower. – Cyber Security for Female Students workshop, gaining practical, hands-on experience in cybersecurity while exploring education and career opportunities in the field. Read More
Four members of our Machine Learning and Data Mining (MLDM) team – Tanja Šarčević, Yelyzaveta Klysa, Sabina Khazari, and Daryna Oliynyk – competed as team “4 braincells” in the Grand Finale of the CISPA European Cybersecurity & AI Hackathon Championship, finishing an impressive 4th place. Read More
Our colleague Walid Fdhila, senior researcher and team lead at SBA Research and senior researcher at the University of Vienna at the Faculty of Computer Science, gave a talk titled Trustworthy Decentralized Digital Ecosystems, during his stay as guest professor at the Faculty of Sciences and Techniques, Université de Tours, France. Read More
We congratulate our key researcher Maria Christakis, and Head of the Research Unit Software Engineering at TU Wien Informatics, on receiving a prestigious European Research Council (ERC) Proof of Concept Grant for her project CIRCUZZ. Read More
The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or “Admin” role. This exposure allows potential unauthorized access to network devices. Read More
SBA Research was proud to support OWASP Global AppSec EU 2026, one of Europe's leading conferences on application security, held from June 22–26, 2026, at the Austria Center Vienna.. The event brought together security researchers, practitioners, and industry experts to exchange knowledge, discuss emerging threats, and explore the latest developments in application security. Read More
SBA Research has proudly supported BSidesVienna as a Gold Sponsor for several years. We’re committed to fostering independent security research and collaboration within the cybersecurity community, and BSidesVienna is an excellent platform for advancing these goals. Read More
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. Read More
How can technology contribute to peace? And what responsibility do today's innovators carry?
Together with the PeaceTech Alliance and AIT Austrian Institute of Technology, SBA Research had the privilege of welcoming Hiroshima survivor and Nobel Peace Prize laureate Setsuko Thurlow to Vienna for the event "Hiroshima's Message for Tech Students and Innovators Today." Read More
On June 23, David Schmidt successfully defended his dissertation, “Hidden Dangers: Uncovering Security and Privacy Risks Through Large-scale Mobile App Analysis,” and received excellent evaluations.
Edgar Weippl, Sebastian Schrittwieser, and Karen Azari supervised the dissertation, while Christopher Kruegel and Thijs van Ede served as reviewer. Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞