SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user. We recommend to update CloudLinux CageFS to version 7.1.2-2 or later. For further details, see the full security advisory. Read More
Sebastian Raubitzek and Kevin Mallinger have been invited for a special research seminar in CGIAR (Consultative Group on International Agricultural Research) about the application of complexity science in Artificial Intelligence. The talk focused on the possibility to enhance AI capacities for sustainability and productivity… Read More
Christopher Kruegel, a longtime collaborator, will chair our Scientific Advisory Board. He has published more than 89 papers at the 4 major security conferences and founded Lastline (later acquired by VMware) by building on the results of Ulrich Bayer‘s… Read More
We are pleased to announce that Maria Christakis joined SBA’s new COMET proposal Next Generation Cybersecurity (SBA-K1 NGC) as member of the scientific and innovation board, Laura Kovacs and Matteo Maffei joined as key researchers. Maria Christakis’s ERC grant focuses on improving software testing,… Read More
Anastasia Pustozerova is researcher at SBA Research and gave an interesting talk on Differential Privacy for Machine Learning. Talk Abstract Machine Learning requires a lot of data to train effective models. Data owners might not be willing to share the data because of its private nature. Differential Privacy can… Read More
MOKOSmart MKGW1 Gateway devices with firmware version 1.1.1 do not provide an adequate session management for the administrative web interface. This allows adjacent attackers with access to the management network to read and modify the configuration of the device. Read More
On Oct 17, 2023, Bernhard Garn joined as MC member of Austria the meeting MC1 of the COST Action NERO (CA22164 – european Network on Extreme fiRe behaviOr). Copyright: MATRIS This meeting marks the start of this COST Action, which focuses… Read More
The 18th International Conference on Availability, Reliability, and Security (ARES 2023) took center stage in Benevento, Italy, from August 29 to September 1, 2023, offering a platform for experts and enthusiasts to explore the latest developments in the field. Co-located with ARES 2023 was the International IFIP Cross Domain Conference… Read More
We had the great pleasure of hosting the first policy dialogue and study visit within the Mutual Learning Exercise on Knowledge Valorisation from June 19-20, 2023 in Vienna. Over the course of two days, the participants engaged in extensive discussions on incentives and skills for research… Read More
Vtiger CRM 7.4.0 or below is prone to a stored cross-site scripting vulnerability in the email templates module due to insufficient sanitizing. Read More