SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
On June 23, David Schmidt successfully defended his dissertation, “Hidden Dangers: Uncovering Security and Privacy Risks Through Large-scale Mobile App Analysis,” and received excellent evaluations.
Edgar Weippl, Sebastian Schrittwieser, and Karen Azari supervised the dissertation, while Christopher Kruegel and Thijs van Ede served as reviewer. Read More
On February 19, Gabriel Gegenhuber successfully passed his Rigorosum with excellent evaluations, defending his dissertation "Democratizing Measurement of Critical Mobile Infrastructure: Security and Privacy in an Increasingly Centralized Communication Ecosystem" before the committee and PhD supervisor Johanna Ullrich. ... Read More
On February 19, Florian Holzbauer successfully completed his Rigorosum, receiving excellent evaluations.
He successfully defended his dissertation, “Turning Failure into Knowledge: Extending the Observable Internet by Leveraging Delivery Failures,” before the committee and Florian’s PhD thesis supervisor Johanna Ullrich. ... Read More
On Monday, October 9, 2023, Bernhard successfully defended his doctoral thesis titled ‘Design Theory Methods and their Applications to the Science of Security’ in his defensio. The committee was chaired by Martina Lindorfer (TU Wien) and in addition consisted of Edgar Weippl (University of Vienna), Rachel… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞