🟠 High  |  Source: The Hacker News


Thermo Fisher Scientific has patched a vulnerability (CVE-2026-17583) in its Applied Biosystems human identification software that could allow attackers to silently alter DNA analysis files (.fsa and .hid formats) before they are loaded by analysis software. If laboratory access controls are bypassed, tampered forensic or clinical DNA data could go undetected. This is particularly serious given the software’s use in forensic investigations and human identification workflows.

Security Architect’s Take: If your organisation processes or stores Applied Biosystems HID software outputs in cloud environments, prioritise patching to the fixed version immediately and review access controls around file storage and pipeline ingestion points. Additionally, implement file integrity monitoring (e.g. cryptographic hashing) on .fsa and .hid files at rest and in transit to detect unauthorised tampering independently of the application layer.

Original advisory: Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable