Thermo Fisher Scientific has released security updates for a vulnerability affecting several Applied Biosystems products used by forensic and human-identification laboratories. The vulnerability, tracked as CVE-2026-17583, has been rated high severity with a CVSS score of 8.2 and could allow DNA data files to be modified before they are opened by analysis software.
The affected files include `.fsa` and `.hid` formats generated during DNA-testing workflows. According to the advisory, an attacker who bypasses laboratory security controls and obtains local or remote access to the relevant systems may be able to alter these files in a manner that is difficult to detect.
This issue is particularly serious because the integrity of forensic DNA data can directly influence criminal investigations, court proceedings, identity verification and other sensitive decisions. A manipulated digital file could potentially change how DNA evidence is interpreted even though the original physical DNA sample remains unchanged.
The vulnerability demonstrates that protecting laboratory equipment alone is not sufficient. The digital information generated by scientific instruments must also be protected throughout its complete lifecycle, including creation, transfer, storage, analysis, backup and presentation as evidence.
Why undetectable modification is so dangerous
Ordinary data theft primarily affects confidentiality, while this vulnerability threatens integrity. An attacker may not need to steal or destroy information if they can quietly change it and allow investigators to continue trusting the manipulated result.
A modified DNA file could potentially add, remove or alter genetic information before it reaches the analysis application. If the software has no reliable mechanism for confirming that the file remains identical to the original instrument output, the altered file may appear legitimate.
This creates a significant forensic challenge because the system may continue functioning normally. There may be no malware warning, system outage or obvious corruption message. The danger lies precisely in the fact that the modified evidence could remain usable and believable.
Integrity failures can therefore be more difficult to discover than conventional cyberattacks. A stolen file may trigger an alert, while a carefully manipulated file may continue through the normal investigative process without attracting attention.
Digital signatures provide stronger verification
Thermo Fisher has introduced digital signatures in updated product versions to help customers verify that files have not been modified after generation. A valid digital signature provides cryptographic evidence that the file originated from the expected system and has not changed since it was signed.
If even a small portion of the protected file is altered, signature verification should fail, warning the laboratory that the data can no longer be trusted without further investigation.
This is an important improvement because file names, timestamps and access permissions alone cannot reliably prove integrity. These values may also be changed by someone with sufficient access.
Digital signatures create a stronger relationship between the instrument output and the file later loaded into analysis software. However, they primarily protect files produced after the updated software has been installed and correctly configured.
The vendor’s advisory does not establish a general method for retrospectively validating every historical file created before digital signing was introduced. Laboratories should therefore avoid assuming that installing the update automatically proves the integrity of previously generated evidence.
Affected and unsupported systems require attention
The vulnerability affects supported versions of several Applied Biosystems product lines, including software used with the 3500 and 3730 Series genetic analysers, SeqStudio systems and GeneMapper ID-X. Thermo Fisher has released corrected versions that laboratories should deploy as soon as practical.
Several older products have reached end of life and will not receive vendor updates. Organizations still using these systems face a more difficult decision because the underlying integrity weakness cannot be corrected through an official software patch.
Unsupported forensic systems should not remain in ordinary production merely because they continue to function. A device may still produce results while lacking modern integrity protection, security updates and vendor support.
Laboratories unable to replace an affected end-of-life system immediately should isolate it, severely restrict access and introduce independent controls around every generated file. Migration to a supported platform should be treated as a security and evidentiary requirement rather than a routine equipment refresh.
Access to laboratory systems must be restricted
The vulnerability reportedly requires the attacker to obtain access to laboratory servers or related systems. This means strong access control can substantially reduce the likelihood of exploitation.
Instrument and analysis systems should be accessible only to authorised personnel and services. Administrative access should use separate privileged accounts, strong authentication and detailed logging.
Laboratories should remove dormant accounts, restrict remote access and avoid allowing shared credentials that make it impossible to determine who accessed or changed a system.
Least privilege is especially important. A user who only needs to analyse files should not automatically receive permission to modify original instrument outputs, alter storage locations or administer the server.
Network connectivity should also be limited. Scientific instruments and forensic analysis platforms generally should not have unrestricted internet access or broad communication with ordinary office networks.
Segmentation can reduce the risk that a phishing infection or compromised employee workstation eventually reaches sensitive laboratory data.
Chain of custody must include digital evidence
Forensic laboratories already maintain strict procedures for physical evidence, documenting who collected it, where it was stored and who handled it. Digital files generated from that evidence require the same discipline.
A trustworthy digital chain of custody should record when a file was created, which instrument generated it, where it was stored, who accessed it, whether it was copied and which version was used during analysis.
Original files should be stored in protected, access-controlled repositories. Analysts should work from verified copies where appropriate rather than repeatedly modifying or transferring the original output.
Logs should be retained centrally and protected from alteration. If an attacker can modify both the DNA file and its local access history, reconstructing what happened becomes considerably more difficult.
Organizations should also calculate secure cryptographic hashes when files are created or received. Hashes do not replace digital signatures, but they can help demonstrate whether a file has changed between documented stages of the workflow.
Backups must preserve integrity as well as availability
Backups are commonly associated with recovery from deletion, ransomware or hardware failure. In forensic environments, they must also help recover from silent data manipulation.
Versioned and immutable backups can allow investigators to compare a suspicious file with an earlier protected copy. However, backups provide limited value if corrupted or manipulated files overwrite every previous version.
Backup systems should retain historical versions, restrict deletion and prevent ordinary laboratory accounts from modifying protected copies.
Recovery procedures should be tested periodically so that laboratories know they can restore both the data and the documentation needed to prove its chain of custody.
The wider cybersecurity lesson
The Thermo Fisher vulnerability demonstrates that cybersecurity in laboratories is not limited to protecting personal information or preventing equipment downtime. It also involves ensuring that scientific and forensic results remain authentic, accurate and defensible.
A digital DNA file may influence decisions involving criminal responsibility, innocence and personal identity. The systems creating and processing that file must therefore provide protection comparable to the care applied to the physical evidence itself.
Organizations using affected Thermo Fisher products should install the corrected versions, verify that digital-signature functionality is operating properly, restrict access to instrument and analysis systems and review the handling of historical files.
Laboratories using unsupported products should evaluate replacement urgently and introduce strict compensating controls until migration is complete.
The incident reinforces a basic security principle: information does not need to be stolen to cause serious harm. Sometimes changing trusted data while leaving every system apparently operational can be considerably more damaging.
When scientific evidence affects life, liberty and justice, data integrity cannot remain an optional technical feature added after researchers demonstrate how easily the files can be manipulated.

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as CVE-2026-17583 and rates it
Source: Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable via The Hacker News — published 03 Aug 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.