SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Today, we celebrate Safer Internet Day—an initiative dedicated to promoting safer and more responsible use of digital technologies. We’re proud to take action not just today, but throughout the entire year, with activities focused on cybersecurity awareness and skills development:… Read More
The 19th International Conference on Availability, Reliability, and Security (ARES 2024) took center stage in Vienna from July 30 to August 2, 2024, offering a platform for experts and enthusiasts to explore the latest developments in the field. Co-located with ARES 2024 was the International Workshop on Dynamics of Disasters:… Read More
The 18th International Conference on Availability, Reliability, and Security (ARES 2023) took center stage in Benevento, Italy, from August 29 to September 1, 2023, offering a platform for experts and enthusiasts to explore the latest developments in the field. Co-located with ARES 2023 was the International IFIP Cross Domain Conference… Read More
Reinhard Kugler held the opening talk of this year’s Hagenberg Forum. He showed current challenges in the automotive domain and how to get started in security testing of electronic control units. Reinhard showed vulnerabilies and testing methods of automotive applications, focusing on… Read More
Gerald Sendera, data protection supervisor & legal counsel at SBA Research, moderated a Round Table at PriSec 2020 – Jahresforum für Privacy & Security – on the topic of Corona Prevention & Data Protection Limits. In the run-up to the event,… Read More
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. ∞