Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Does image show gorilla ‘screaming for help’ after caretaker collapsed?

    August 3, 2026

    After Trump Pardon, Former Honduras President Hernández Faces Charges in His Home Country

    August 3, 2026

    Reform UK would use Royal Navy to stop small boats

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Does image show gorilla ‘screaming for help’ after caretaker collapsed?
    • After Trump Pardon, Former Honduras President Hernández Faces Charges in His Home Country
    • Reform UK would use Royal Navy to stop small boats
    • Standards watchdog investigating Reform UK’s Richard Tice | Richard Tice
    • A Marc Benioff-backed startup thinks AI can solve the AI deployment problem
    • Stop depending on heroics and start operationalizing third-party risk
    • Five days, a 30% chance, and a battle over Trump’s crypto profits: Inside the Senate’s scramble to pass CLARITY Act before Friday
    • Huisman equipment ordered for SBM Offshore and Solstad’s installation vessel
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 3, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 03, 2026Data Security / Vulnerability

    Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.

    The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.

    Thermo Fisher tracks the issue as CVE-2026-17583 and rates it High with a CVSS v4.0 score of 8.2. Five supported product lines have received updates that add digital signatures, while three end-of-life data collection products will receive no vendor update.

    Thermo Fisher credits Nathan Adams, Kevin Dyer and Laura Gaydosh Combs, together with the U.S. Cybersecurity and Infrastructure Security Agency, with identifying the issue and coordinating disclosure.

    Thermo Fisher urged customers to install the applicable updates. For customers unable to implement the updates or use another third-party analysis platform, the company recommends controls covering file custody, storage, access, privilege and network connectivity.

    Cybersecurity

    The public bulletin does not address exploitation, but Thermo Fisher separately told The Wall Street Journal that it knew of no instances in which the vulnerability had been exploited.

    In its security bulletin, Thermo Fisher says the files can be modified before analysis software loads them. The updates implement digital signatures that, moving forward, help customers verify that data files have not been changed.

    The Journal reported that Nathan Adams, a systems engineer at Forensic Bioinformatics, tested the issue using a public data set. Adams said his first successful file modification using Anthropic’s Claude took about 45 minutes.

    In a demonstration viewed by the Journal, his code combined scans from two individual DNA profiles into a new file that appeared untouched since 2015. The modified file raised no warning in analysis software used by many laboratories.

    Thermo Fisher’s bulletin does not specify the access required. The researchers told the Journal that an attacker would need local or remote access to a laboratory’s servers and enough knowledge of how DNA testing works.

    The updates cover five Applied Biosystems human identification product lines:

    • 3500/3500xL Series Data Collection Software 4.0.2 and earlier, fixed in 4.0.3
    • 3730/3730xL Series Data Collection Software 5.0.2 and earlier, fixed in 5.0.3
    • SeqStudio Genetic Analyzer Data Collection Software 1.2.5 and earlier, fixed in 1.2.6
    • SeqStudio Flex Series Instrument Software 1.2.0 and earlier, fixed in 1.2.1. Labs using SeqStudio Flex with security, audit, and electronic signature (SAE) enabled must first install the latest SAE profile on the SAE Admin Console
    • GeneMapper ID-X Software v1.7.3 and earlier, fixed in v1.7.4

    Three older lines get nothing: 3130 Series Data Collection Software 4.1 and earlier, ABI PRISM 3100/3100-Avant Data Collection Software 2.0 and earlier, and ABI PRISM 310 Data Collection Software 3.1 and earlier. Thermo Fisher says each has reached end of life and will receive no update.

    Thermo Fisher’s recommended measures for customers unable to implement the updates or use another third-party analysis platform include maintaining chain of custody, storing files on encrypted and password-protected media, restricting access, applying least privilege on instrument and analysis systems, and limiting internet connectivity to trusted sources.

    Cybersecurity

    As of August 3, 2026, exact-identifier checks by The Hacker News found Thermo Fisher’s bulletin but no separate CVE.org or National Vulnerability Database detail page for CVE-2026-17583.

    The identifier was not listed in CISA’s Known Exploited Vulnerabilities catalog. Thermo Fisher’s public security-bulletin index also did not list the July 31 notice.

    Thermo Fisher says the signatures will help customers verify files “moving forward.” The bulletin does not explain whether files generated before the updates can be validated retroactively or how laboratories should validate them. The Hacker News found no public primary source linking altered casework to the flaw as of August 3, 2026.

    The researchers told the Journal that the vulnerability likely existed in digital files produced by crime-lab machines since 1995 and that they had not found a way to detect prior tampering if it occurred.

    hermo Fisher’s bulletin does not confirm that historical scope. The reported weakness affects digital records generated from DNA testing, not the underlying physical DNA samples.

    DNA File Fisher Flaw Patches Tampering Thermo Undetectable
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Stop depending on heroics and start operationalizing third-party risk

    Coldcard Wallet Flaw Exposes Years Of Bitcoin Seeds After $70M In BTC Stolen

    OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

    COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

    Cancer may be breaking its own DNA to keep growing

    Google Chrome may soon block New Tab hijacker extensions by default

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Does image show gorilla ‘screaming for help’ after caretaker collapsed?

    August 3, 2026

    After Trump Pardon, Former Honduras President Hernández Faces Charges in His Home Country

    August 3, 2026

    Reform UK would use Royal Navy to stop small boats

    August 3, 2026

    Standards watchdog investigating Reform UK’s Richard Tice | Richard Tice

    August 3, 2026
    Latest Posts

    Oil has harmed the nature and people of the Niger Delta; human rights may save it

    July 23, 2026

    Drought announcement looms for parts of Wales over river levels

    July 23, 2026

    Swiss Bank BancaStato Launches Bitcoin Trading Through Sygnum And Avaloq

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Does image show gorilla ‘screaming for help’ after caretaker collapsed?

    August 3, 2026

    After Trump Pardon, Former Honduras President Hernández Faces Charges in His Home Country

    August 3, 2026

    Reform UK would use Royal Navy to stop small boats

    August 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.