SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Dominique Schröder, key researcher at SBA Research and full professor of Privacy Enhancing Technologies at TU Wien published a new paper titled "Password-Hardened Encryption Revisited" which was presented at the 31st ASIACRYPT 2025 Melbourne, VIC, Australia. ... Read More
LibreChat version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. This allows attackers to interact with arbitrary third-party HTTP services, for example the internal RAG API. ... Read More
At the end of November, our colleague Daryna Oliynyk, a researcher at SBA Research and the Security and Privacy Research Group at the University of Vienna, was invited to speak at the European Symposium on Security and AI (ESSAI) in Rennes, France. She presented the joint paper "Attackers Can Do Better: Over- and Understated Factors of Model Stealing Attacks", co-authored with Rudolf Mayer and Andreas Rauber. ... Read More
Tanja Sarcevic, Daryna Olyinyk, and Yelyzaveta Klysa, all MLDM research group members, and Sabina Khazari participated in the European Cybersecurity & AI Hackathon Championship organized by CISPA, one of Europe’s leading research centers in cybersecurity and artificial intelligence. Congratulations to them, they won 2nd place and qualified themselves to the grand finale that will be held in St. Ingbert, Germany, in June 2026. ... Read More
We are pleased to announce that the SBA Security Meetup is now officially operating as the OWASP Vienna Chapter. While the name has evolved, our mission remains unchanged: strengthening the exchange of ideas, knowledge, and experience within the information security community. What started as the SBA… Read More
Florian Holzbauer, researcher at SBA Research, and Gabriel Gegenhuber, researcher at SBA Research and the Research Group Security and Privacy at the University of Vienna, attended the Annual Computer Security Applications Conference (ACSAC) 2025 in Hawaii, USA. ... Read More
On December 2, 2025, the OCG Working Group on Sustainability & Computer Science marked the beginning of a new phase of collaboration with an interdisciplinary and transdisciplinary kick-off meeting. Chaired by Kevin Mallinger, lead of the CORE Research Group at SBA Research, the meeting focused on the central theme “AI and Farming” – an area where sustainable computing has the potential to create significant impact... Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞