Thenextweb AI Exploit in Crime Lab Software Enables Undetectable DNA Evidence Tampering
Article Content
- •CVE-2026-17583 allows undetectable tampering of DNA evidence files.
- •The vulnerability requires local access to exploit, posing risks from insiders or intruders.
- •Thermo Fisher's patch only protects future files, leaving past evidence unverifiable.
A critical flaw in Thermo Fisher Scientific's crime lab software allows unauthorized users to alter DNA evidence files without detection. The vulnerability, identified as CVE-2026-17583, has existed since 1995 and affects several Applied Biosystems tools. An attacker with local access can modify .fsa and .hid files, potentially framing innocent individuals or erasing suspects. The flaw was demonstrated using AI tools, with edits made in just 45 minutes. Although Thermo Fisher has issued a patch, it only protects future files, leaving past evidence unverifiable. No known cases of exploitation have been reported, but the potential for misuse raises significant concerns among forensic scientists. The vulnerability has not yet been listed in national databases, indicating a lack of awareness in the broader cybersecurity community.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Thermo Fisher Scientific and CVE-2026-17583 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…