Thenextweb
AI Exploit in Crime Lab Software Enables Undetectable DNA Evidence Tampering
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical flaw in Thermo Fisher Scientific's crime lab software allows unauthorized users to alter DNA evidence files without detection. The vulnerability, identified as CVE-2026-17583, has existed since 1995 and affects several Applied Biosystems tools. An attacker with local access can modify .fsa and .hid files, potentially framing innocent individuals or erasing suspects. The flaw was demonstrated using AI tools, with edits made in just 45 minutes. Although Thermo Fisher has issued a patch, it only protects future files, leaving past evidence unverifiable. No known cases of exploitation have been reported, but the potential for misuse raises significant concerns among forensic scientists. The vulnerability has not yet been listed in national databases, indicating a lack of awareness in the broader cybersecurity community.
Key Points: • CVE-2026-17583 allows undetectable tampering of DNA evidence files. • The vulnerability requires local access to exploit, posing risks from insiders or intruders. • Thermo Fisher's patch only protects future files, leaving past evidence unverifiable.