SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Alexander Schatten, senior researcher at SBA Research, was interviewed by journalist Daphne Hruby for the current podcast episode "How to become a scientist". ... Read More
Alexander Schatten, senior researcher at SBA Research, got interviewed by journalist Daphne Hruby for the podcast episode "Science under stress: When science is under time pressure", in October. ... Read More
Whether and how the cell phone listens in The phenomenon that you talk about something and then you get on your smartphone the appropriate advertising on the topic. “ZIB Magazin” took a look at whether and how cell phones listen in. Edgar Weippl, research director of SBA Research and full… Read More
Christian Kudera (SBA Research) recently gave an interview on his research project AutoHoney(I)IoT to DiePresse, in which he focuses on IT-security related challenges arising from “Internet of Things” (IoT) and “Industrial Internet of Things” (IIoT) networks. Read the full article &… Read More
The 21th International Conference on Availability, Reliability, and Security (ARES 2026) took center stage in Linköping, Sweden, from August 24 - 27, 2026, offering a platform for experts and enthusiasts to explore the latest developments in the field. The conference was jointly organised by Linköpings universitet (LiU) and SBA Research. ∞
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞