SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Yvonne Poul and Stefan Jakoubi gave a talk today about “Digitization & Information Security – Romeo & Julia?” at the LSZ IT-Security Herbst at Novomatic Forum. Read More
The 12th Plenary of the Research Data Alliance was held 5-8 November 2018 in Gaborone under the theme “The Digital Frontiers of Global Science”. The meeting has gathered scientists, experts and practitioners engaged in the advancement of data-driven science and economy from around… Read More
Some of the vulnerabilities found in the Koha Library software in the past from the combinatorial security testing team of SBA Research, now part of the MaTRIS group, have been officially acknowledged in the CVE-MITRE database.More details can be found below, below: CVE-2015-4631 (Multiple… Read More
Consultant Information Security (Details in German) Junior System Engineer – Vollzeit (m/w) Junior System Engineer – Teilzeit (m/w) Project assistant positions in Mathematics for Testing, Reliability and Information Security Technical IT Security Consultant (Junior/Senior): Professional Services (Details in German)… Read More
Yvonne Poul has successfully completed her MBA studies in “Innovation Management and Entrepreneurship”, conducted by WU Vienna and TU Vienna. Congratulations!… Read More
The IKT-Sicherheitskonferenz hosted by the Austrian Armed Forces has taken place in Alpbach from October 16-17, 2018. In addition to Wilfried Mayer giving a talk on current development in the TOR network SBA has once more hosted the Young Researchers´ Day. IKT-Sicherheitskonferenz… Read More
Philipp Reisinger will hold an exciting talk today entitled “Two Worlds and One Reality – Approaching Security and Risk in the Real and the Virtual World” at the Congress Center Alpbach (IKT Security Conference 2018). Interested people will have the opportunity to attend the talk/lecture also on November 14, in… Read More
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization. We recommend to update Teltonika RUT9XX routers to version RUT9XX_R_00.04.233 or later. For further details, see the full security advisory. Read More
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges. We recommend to update Teltonika RUT9XX routers to version RUT9XX_R_00.04.233 or later. For further details, see the full security advisory. Read More
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. ∞