SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
We extend our warmest congratulations to our key researcher Laura Kovács on her election as a member of the Austrian Academy of Sciences (ÖAW), one of Austria's most prestigious scientific institutions. ... Read More
SBA Research was delighted to welcome FFG Managing Director Karin Tausz and Head of Division Structural Programmes Silvia Laimgruber to the SBA-K1 NGC COMET Center in Vienna. ... Read More
Maria Christakis has been awarded the 2026 ACM-W Rising Star Award, presented by ACM-W: ACM’s Women in Computing. This prestigious recognition honours outstanding early-career researchers who have made exceptional contributions to the computing field. ... Read More
On February 19, Gabriel Gegenhuber successfully passed his Rigorosum with excellent evaluations, defending his dissertation "Democratizing Measurement of Critical Mobile Infrastructure: Security and Privacy in an Increasingly Centralized Communication Ecosystem" before the committee and PhD supervisor Johanna Ullrich. ... Read More
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API. ... Read More
On February 19, Florian Holzbauer successfully completed his Rigorosum, receiving excellent evaluations.
He successfully defended his dissertation, “Turning Failure into Knowledge: Extending the Observable Internet by Leveraging Delivery Failures,” before the committee and Florian’s PhD thesis supervisor Johanna Ullrich. ... Read More
Our colleague Georg Merzdovnik, senior researcher and team lead of research group ISIS at SBA Research, hosted Hacker Jeopardy at Disobey 2026, one of Europe’s most well-known hacker and cybersecurity community events. ... Read More
Checkmk in versions before 2.4.0p22 and 2.3.0p43 is prone to a cross-site scripting (XSS) vulnerability when used in a distributed monitoring setup. Any connected remote site can inject JavaScript code in the central site's user interface. ... Read More
Suprema’s BioStar 2 in version 2.9.11.6 allows users to set new password without providing the current one. Exploiting this flaw combined with other vulnerabilities can lead to unauthorized account access and potential system compromise. ... Read More
In Episode 147 of the Zukunft Denken – Podcast, Alexander Schatten, senior researcher at SBA Research, address this question under the title: “Digital Colony or Sovereignty?” ... Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞