← Back to Tech & Science

Thermo Fisher Issues Patch for Critical Vulnerability in Forensic DNA Software

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

WALTHAM, Mass. — Thermo Fisher Scientific has released a security patch to address a critical vulnerability in select Applied Biosystems human identification software used by forensic laboratories worldwide. The flaw could allow unauthorized actors to alter digital data files before they undergo analysis, potentially compromising the integrity of DNA evidence without leaving immediate traces.

The company announced the update on Monday following coordination with cybersecurity authorities. The vulnerability exists within specific versions of the genetic analysis software widely deployed in criminal justice and research settings. If exploited by an attacker who has circumvented standard laboratory access controls, malicious actors could modify raw data files to change test results or introduce false information into case records.

Thermo Fisher stated that the patch resolves a gap where digital signatures on DNA profile files could be bypassed under specific conditions. The company emphasized that no confirmed incidents of exploitation have been reported in connection with this flaw as of Monday morning. However, cybersecurity officials warn that the potential for undetectable manipulation poses significant risks to forensic investigations and legal proceedings.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed the vulnerability on its Known Exploited Vulnerabilities catalog, urging all users of affected systems to apply the update immediately. The agency highlighted that while physical security measures at laboratories provide a layer of defense, digital vulnerabilities remain a target for sophisticated threats.

Forensic labs utilizing Applied Biosystems platforms are advised to verify their software versions against Thermo Fisher's advisory list and install the corrective patch without delay. The company has provided detailed instructions on its support portal regarding version compatibility and installation procedures to minimize downtime in critical operations.

Security experts note that while the primary risk involves data integrity, the broader implications could extend to public trust in forensic science if evidence is ever shown to be compromised. Thermo Fisher confirmed it is working with affected customers globally to ensure rapid deployment of the fix across all relevant jurisdictions.

Questions remain regarding how long the vulnerability existed prior to its discovery and whether any historical cases might have been impacted by similar, unpatched exploits in previous software versions. As laboratories begin updating their systems, investigators will continue to monitor for signs of active exploitation or attempts to leverage the flaw before patches are fully installed across all facilities.

Discussion

0 / 2000