SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
This year’s WeAreDevelopers Congress 2024, held in Berlin from July 17th to 19th with intriguing sessions covering the latest trends and advancements across the industry. Reinhard Kugler, lead of the MARC team, contributed to the congress with his standout presentations titled “A Hitchhiker’s Guide to Container… Read More
In early March, the MATRIS Applied Research Consulting Team organized the second meetup of the Automotive Security Meetup series for the automotive community at SBA Research. The meeting format of the Automotive Security Research Group (ASRG Vienna) aims to foster discussion about ideas, methods,… Read More
In September 2022, SBA Research held the first Innovation Camp on Automotive Security “AutoCyberSec”, funded by Austrian Research Promotion Agency (FFG). One goal was to bring experts from different domains of safety, security testing and modelling closer together to prepare for the current and… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞