SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Tomasz Miksa held a talk at the 18th RDA Plenary: Biomedical Research Data Management and Sharing: From Policies to Culture Change on November 10, 2021. Title: Fostering cultural change in data sharing on the example of machine actionable Data Management Plans Tomasz was one of the invited speakers whose… Read More
One of our Key Researchers, Johanna Ullrich, was interviewed for the ORF "Dok1" documentary "Nichts geht mehr: Sieben Tage ohne Strom" about an experience of a one-week-blackout. Read More
The “Blockchain” hype of recent years increasingly attracts attention due to the financial aspects of Cryptocurrencies and raises interest in the opportunities offered by the underlying protocols. These technologies, commonly referred to as distributed ledger technologies (DLTs), cover several application areas. The increasing use of DLTs in both large enterprises… Read More
Nicholas Stifter, SBA Research, wrote a great introductory article (in German) on Trust and Blockchains for the OCG magazine (Ausgabe 01-02, 2020). Read the full article here!
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞