First wave of our team (me included) is on the way to @defcon.bsky.social #CTF. Huge thx to the companies and unis backing us, we're extremely grateful.
Special shoutout to @tuwien.at for the early support, as well as everyone who joined after.
We'll give our best, wish us luck!
See you Vegas π΄π©
05.08.2025 20:09 β π 2 π 0 π¬ 0 π 0
Things were a bit different with Android this time, likely due to a functionality vs security trade-off that made it harder to address the issue in AOSP. Going forward, we'll continue reporting to Google but jointly disclose to GrapheneOS for any future Android-related issues.
23.07.2025 00:25 β π 9 π 1 π¬ 0 π 0
Completely agree. For context on our disclosure policy: we usually report issues to upstream first so that other vendors or projects can automatically benefit from the fix. This process has worked well so far with browser vendors. The Chrome team in particular has always been extremely responsive.
23.07.2025 00:25 β π 2 π 0 π¬ 1 π 0
By scanning the QR code you win a free color blindness test
23.07.2025 00:23 β π 1 π 0 π¬ 0 π 0
I'm part of the team that discovered the #TapTrap vulnerability. We confirmed that @grapheneos.org has properly fixed it, as detailed on our site taptrap.click
Despite a small factual error, it's good to see #GrapheneOS getting some media attention.
22.07.2025 18:53 β π 39 π 10 π¬ 1 π 0
foxnews.com/tech/new-and...
> GrapheneOS, a security-focused operating system based on Android, confirmed that its current version is also affected. However, it plans to release a fix in its next update.
No, we said that on July 7 and then shipped grapheneos.org/releases#202... fixing it.
22.07.2025 03:58 β π 75 π 6 π¬ 1 π 2
Team Austria, 1st qualifier event.
ECSC 2025 prep has begun! First Team Austria qualifier wrapped up with 30 participants focusing on #ENOWARS and #DUCTF. Great vibes. Thanks to Ikarus Security for hosting us and everyone who joined! #ECSC2025 @tuwien.at @informatics.tuwien.ac.at @cysecwien.bsky.social
21.07.2025 13:40 β π 1 π 0 π¬ 0 π 0
And shoutout to my girlfriend for lending a hand - literally - for the photo! π
17.07.2025 11:59 β π 2 π 0 π¬ 0 π 0
Our #TapTrap attack got covered in @tuwien.at's news!
This was such a fun project. Congrats to @beerphilipp.bsky.social on his second first-author paper at a top-tier conference β€οΈ
We'll present the paper at #USENIX in Seattle on August 14 . Looking forward to catching up with some of you there!
17.07.2025 11:59 β π 0 π 1 π¬ 2 π 0
Congrats to my co-lecturers @mautem.bsky.social, @matteomaffei.bsky.social, @wert310.bsky.social, Pedro Bernardo, @beerphilipp.bsky.social, Simon Jeanteur and our amazing tutors: this wouldn't be possible without you.
And thanks to all students for the great feedback and participation π
15.07.2025 23:52 β π 3 π 1 π¬ 0 π 0
Das sind die Best Teaching Award-Finalist_innen 2025
Die Jury hat entschieden, fΓΌr wen die Eulenjagd weitergeht.
For the second year in a row, @tuwien.at students have nominated our Introduction to Security course among the finalists for the Best Teaching Award!
Balancing research, teaching & outreach isn't easy, but we give it our all.
π www.tuwien.at/tu-wien/aktu...
CC @informatics.tuwien.ac.at
15.07.2025 23:52 β π 5 π 1 π¬ 1 π 0
ublock origin lite works quite well on Chrome (but please people keep using Firefox)
11.07.2025 21:14 β π 1 π 0 π¬ 0 π 0
This effort is the result of a collab w Sebastian Roth, @lindorfer.in and @beerphilipp.bsky.social who discovered the issue & did the heavy lifting. Thanks to @wwtf.at for making this research possible and supporting us β₯οΈ
See you at #USENIX in Seattle next month!
@tuwien.at @cysecwien.bsky.social
10.07.2025 16:35 β π 2 π 0 π¬ 0 π 0
It works on Android 15 & 16, while @grapheneos.org issued a fix. Major browsers such as Chrome and Firefox promptly patched after we disclosed the vulnerability. We analyzed ~100K Play Store apps finding that TapTrap is not currently being exploited in the wild.
10.07.2025 16:35 β π 2 π 1 π¬ 1 π 0
Unlike classic tapjacking, TapTrap uses Android's built-in activity transition animations to launch a transparent activity on top of the attacker's app. The user thinks they're tapping a harmless button, but the tap goes to a permission/system prompt, a browser, or a sensitive app without notice.
10.07.2025 16:35 β π 0 π 0 π¬ 1 π 0
TapTrap: AnimationβDriven Tapjacking on Android
Our new Android attack, #TapTrap, is getting media coverage β so here's a quick explainer.
It's a new tapjacking technique that exploits Android's UI animations to hijack user taps without requiring any permissions. @beerphilipp.bsky.social will present it at #USENIX Sec'25.
π taptrap.click
10.07.2025 16:35 β π 5 π 2 π¬ 1 π 0
It has been an honor to organize the bootcamp for 3 years in a row, and I am proud that it's getting better every time. Thanks to CSA, @cysecwien.bsky.social, ENISA, Joe Pichlmayer, Manuel Reinsperger and the entire team for making this possible.
See you all next year β₯οΈ #CYBER #ECSC2025
10.07.2025 15:39 β π 2 π 0 π¬ 0 π 0
Help us choose our mascot! πΎ
Nautilus Institute is asking us to send them a animal mascot for the DEFCON CTF, and we need your help to pick the cutest contender!
Dive into the threat to meet the 8 adorable candidates.
#KuKHofhackerei #defcon33 #ctf #Mascot
12.06.2025 12:59 β π 2 π 1 π¬ 1 π 0
KuK Hofhackerei - DEF CON 33 Sponsorship (Front)
KuK Hofhackerei - DEF CON 33 Sponsorship (Description)
KuK Hofhackerei - DEF CON 33 Sponsorship (Packages)
My team @kukhofhackerei.bsky.social is heading to the DEF CON CTF finals this August in Las Vegas π₯
We're now looking for sponsors to help cover the trip. If you're interested in supporting us, please get in touch or share this around.
Call for sponsors at hofhackerei.at π¦πΉ
Thank you!
#CTF #DC33
15.05.2025 15:08 β π 4 π 2 π¬ 0 π 0
After many years of battles with @mhackeroni.bsky.social, I'm blown away to announce that we've qualified for the #DEFCON CTF finals with KuK Hofhackerei π¦πΉ this year!
New friends, same love. Couldn't be prouder of this team.
Thanks to nautilus.institute for organizing and see you in Vegas! π©
14.04.2025 12:54 β π 8 π 0 π¬ 1 π 1
Austria Cyber Security Challenge 2025
The 2nd wave of challenges for the Austria Cyber Security Challenge #ACSC will be live in 1h! You have 1 month left to compete and prove your skills!
I contributed a hard web challenge this time, let's see who can solve it π
Ready? π acsc.land
@informatics.tuwien.ac.at @cysecwien.bsky.social
01.04.2025 14:59 β π 0 π 1 π¬ 0 π 0
Best paper award ceremony at MADWeb 2025
And the best paper award sponsored by @paloaltonetworks.bsky.social goes to...
π Can Public IP Blocklists Explain Internet Radiation?
by D. Ravalico, S. Cossaro, R. Valentim, M. Trevisan, and I. Drago!
Congratulations π
#MADWeb #NDSSsymposium2025
02.03.2025 18:05 β π 4 π 2 π¬ 0 π 0
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
Can't wait for Friday? Get a sneak peek at #MADWeb '25 papers now! πβ¨ All papers are live on our website: madweb.work
Safe travels, and see you in San Diego! βοΈ
#NDSSsymposium2025
26.02.2025 23:19 β π 3 π 1 π¬ 0 π 0
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
We're thrilled to announce Nick Nikiforakis (Stony Brook University) as our first keynote speaker of #MADWeb '25!
π€ Building on Top of Shifting Sands: Web Security Through the Lens of Content Integrity
Don't miss it!
See the full program at madweb.work
12.02.2025 12:55 β π 3 π 2 π¬ 0 π 0
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
Our 2nd Keynote is here! π¨
We're excited to have Frederik Braun @freddyb.bsky.social (Mozilla) at #MADWeb '25!
π€ With Carrots & Sticks: Can the Browser Handle Web Security?
Join us in San Diego to attend this session!
Full program: madweb.work#program
12.02.2025 13:04 β π 3 π 1 π¬ 0 π 0
MADWeb
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb)
The #MADWeb '25 program is live!
We've got 9 full papers, 3 work-in-progress papers, and 2 exciting keynotes lined up. Huge thanks to all the authors and the program committee!
Check out the details and get ready for a great event! π₯
π madweb.work#program
See you in San Diego! #NDSS #websecurity
12.02.2025 12:24 β π 2 π 2 π¬ 0 π 0
MADWeb 2025
π¨ Deadline Extended π¨
By popular demand, the #MADWeb submission deadline is now January 14, 2025 (AoE)! ποΈ
You still have 1 week to send your papers and join us in San Diego!
π Submit here: madweb25.hotcrp.com
π Details: madweb.work
Spread the word!
#websec #cfp #ndss
08.01.2025 15:43 β π 2 π 1 π¬ 0 π 1
Please consider submitting your work and help us spread the word! #MADWeb
06.01.2025 15:56 β π 4 π 1 π¬ 0 π 0
Help us make this year's edition of #MADWeb the best one yet!
π
Deadline: January 9, 2025 (AoE)
π Submit here: madweb25.hotcrp.com
π Website: madweb.work
#CfP #websec #websecurity
29.12.2024 13:19 β π 3 π 0 π¬ 0 π 0
Austrian CTF team merger π¦πΉ
https://hofhackerei.at
Open source privacy and security focused mobile OS with Android app compatibility.
https://grapheneos.org/
Software developer.
Still taking care of Clipperz: clipperz.is
The Vienna Science and Technology Fund is a non-profit organisation to promote science and research in Vienna.
Unter dem Motto "Technik fΓΌr Menschen" wird an der Technischen UniversitΓ€t Wien seit mehr als 200 Jahren geforscht, gelehrt und gelernt.
https://www.tuwien.at
phd βͺ@ucdavis | web privacy and security researcher
Professor at Paderborn University, co-founder of Hackmanit. Used to break XML, now playing with TLS and crypto. Co-author of DROWN, EFAIL, and TLS-Attacker.
Apple Security Researcher | Informatics PhD | TUGraz Alumni | Pwnie Award 2022 | BlackHat Speaker | Power Analysis | Fault Attacks | ΞΌ-Architectural Attacks | https://andreaskogler.com/
Assistant professor at the Washington University in St. Louis. I research computer security and privacy.
Microarchitectural Security | PhD Student @ #CISPA
https://d-we.me
Security, privacy, cellular, living in clouds; night-owl; PostDoc CISPA; former UCI, SBA, TU Wien, iSeclab. My own opinions. May contain sarcasm.
Botanical Art | Drawing | Printmaking
The MADWeb workshop aims to make the Web safer by discussing security and privacy challenges in the face of the rapid evolution of the Web. #MADWeb
Postdoctoral researcher in cryptography at ENS Paris
erkantairi.com
Researcher at @cnrs.bsky.social in the Spirals team. Browser fingerprinting, web privacy and security, software engineering. Creator of http://AmIUnique.org.
Postdoc at TU Wien
Opinions my own
Standing in the wind
Computer Science Education Researcher @TU Wien | Teaching CS & Math | Hobby musician & outdoor enthusiast
We Are Europe's Research Center Translating Data into Solutions for a Better World
Faculty of Informatics at TU Wien in Vienna, Austria