SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Read More
In 2025, the Austrian Computer Society (OCG) once again recognizes outstanding academic work in the fields of Computer Science and Business Informatics with the OCG Förderpreis and the OCG Förderpreis-FH. This year’s OCG Förderpreis goes to our research colleague Daryna Oliynyk for… Read More
Bluetooth Low Energy is one of the most widely used protocols used in Internet of Things (IoT) and multimedia devices. Security issues in these applications are prone to affect a significant number of end users and companies alike. In their latest work applying the Combinatorial Security Testing (CST) approach… Read More
The research on Combinatorial Security Testing (CST) by the MATRIS group of SBA Research is amongst the top five nominations for the Houska prize, Austria's largest private award for application-oriented research, in the category non-university research. ... Read More
We are proud to announce that we have been awarded the 2025 Swift Provider – Customer Security Programme Assessment label by Swift. This prestigious recognition highlights our commitment to maintaining high cybersecurity standards and excellence in customer security assessments. The label was granted following a rigorous… Read More
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route parameters in the debug-mode error page. Read More
The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page. Read More
The research project combinatorial security testing of the MATRIS Research Group has been nominated in the category Non-University Research for the 2025 Houska Prize! Since its establishment in 2005, the Houska Prize is sponsored… Read More
For decades, AI systems have been used to defend against cyberattacks. However, modern AI, particularly generative AI, not only strengthens defense mechanisms but also introduces new attack methods. A study conducted by SBA Research on behalf of RTR examined the latest advancements in cybersecurity from both offensive (Red Team) and… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞