SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Researchers from SBA Research, the Security and Privacy Research Group at the University of Vienna and the UniVie Doctoral School Computer Science, have been honored with the Best Paper Award at the 28th International Symposium on Research in Attacks, Intrusions and Defenses… Read More
In mid-October, our yearly partner and friends of SBA Research event IMPACT brought together experts, practitioners, and decision-makers from research, industry, and the open-source community. One afternoon with discussion about the latest developments in security, open source, and research and to celebrate our long-standing relationships. This year’s program… Read More
We are proud to announce that we joined the Linux Foundation Europe, further strengthening our role within the international open-source community. With this step, we are reinforcing our commitment to advancing security and resilience in digital infrastructures. ... Read More
David Schmidt, PhD student at CD-Lab AsTra, Sebastian Schrittwieser, key researcher at SBA Research and head of the CD-Lab, and Edgar Weippl, scientific director at SBA Research and full professor for security & privacy at the University of Vienna, received the Distinguished Paper Award at ACM CCS 2025 (A*-rated) for their work Leaky Apps: Large-scale Analysis of Secrets Distributed in Android and iOS Apps. ... Read More
Our colleagues Georg Goldenits, and Thomas Neubauer published a new paper on Taxonomy of cybersecurity consideration in agriculture. This paper explores the key cybersecurity threats and reliability risks in Agriculture 4.0 by mapping potential faults and pitfalls to emerging digital technologies in farming. It also discusses countermeasures, legal frameworks,… Read More
From September 19 to 21, around 65 talented and curious women and FINTA* immersed themselves in the exciting world of cybersecurity at the University of Vienna. This continuing education and networking program is unique in Europe and is designed to make it easier to enter and advance in IT security. ... Read More
The 20th International Conference on Availability, Reliability, and Security (ARES 2025) took center stage in Ghent, Belgium, from August 11-14, 2025, offering a platform for experts and enthusiasts to explore the latest developments in the field. Co-located with ARES 2025 was the 8th International Symposium for Industrial Control System & SCADA Cyber Security Research.... Read More
We are incredibly proud of the Austrian hacking team KuK Hofhackerei, which secured 9th place at DEF CON CTF 33, one of the toughest and most renowned Capture the Flag competitions in the world. The DEF CON Capture the Flag competition is… Read More
Vulnerability Overview All user accounts authenticate towards a Filebrowser instance with a password. A missing password policy and brute-force protection makes it impossible for administrators to properly secure the authentication process. Recommended Countermeasure We recommend to update to Filebrowser version 2.34.1 or later and configure… Read More
Vulnerability Overview Files managed by Filebrowser can be shared with a link to external persons. While the application allows protecting those links with a password, the implementation is error-prone, making an incidental unprotected sharing of a file possible. Recommended Countermeasure We recommend to update to… Read More
We are proud to announce that we joined the Linux Foundation Europe, further strengthening our role within the international open-source community. With this step, we are reinforcing our commitment to advancing security and resilience in digital infrastructures. ... ∞