Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Thermo Fisher Fixes DNA Software Vulnerability

Thermo Fisher Fixes DNA Software Vulnerability

Posted on August 3, 2026 By CWS

Thermo Fisher’s Crucial Software Update

Thermo Fisher Scientific has issued a critical update for its Applied Biosystems human identification software, addressing a flaw that could enable undetectable data modifications. The vulnerability, identified as CVE-2026-17583, allows changes to .fsa and .hid files before analysis. This issue has been rated as ‘High’ with a CVSS v4.0 score of 8.2, necessitating immediate attention from users.

Security Bulletin and Product Impact

According to Thermo Fisher’s July 31 security bulletin, the flaw affects five supported software lines, which have now been updated to incorporate digital signatures for data verification. Unfortunately, three legacy data collection products will not receive updates due to their end-of-life status. Recognition for identifying and disclosing the vulnerability goes to Nathan Adams, Kevin Dyer, Laura Gaydosh Combs, and the U.S. Cybersecurity and Infrastructure Security Agency.

Thermo Fisher strongly advises its customers to install the updates to ensure data integrity. For those unable to apply the patches or switch to alternative platforms, the company recommends stringent controls over file custody and access, along with network security measures.

Exploitation and Prevention Measures

While Thermo Fisher has not publicly reported any exploitation incidents, they informed The Wall Street Journal that no known cases exist. The updates are designed to prevent unauthorized modifications by introducing digital signatures, assuring users of data authenticity from this point onward.

Forensic Bioinformatics systems engineer Nathan Adams demonstrated the flaw’s potential impact by modifying a DNA profile file using Anthropic’s Claude. His test highlighted the ease with which files could be altered without detection, emphasizing the importance of Thermo Fisher’s security enhancements.

Software Updates and Recommendations

The update covers several Applied Biosystems product lines, including the 3500/3500xL and 3730/3730xL Series, SeqStudio Genetic Analyzer, SeqStudio Flex Series, and GeneMapper ID-X Software. Users are urged to implement these updates to safeguard their DNA data processes. However, older models like the 3130 Series and ABI PRISM lines will not receive updates. To mitigate risks, Thermo Fisher suggests using encrypted storage, restricting access, and enforcing strict network policies.

Despite the updates, questions remain about the historical scope of the vulnerability, with researchers noting potential undetected tampering dating back to 1995. The security bulletin does not clarify whether pre-update files can be authenticated, leaving some concerns unresolved.

Conclusion

Thermo Fisher’s proactive response to the DNA software vulnerability marks a crucial step forward in securing forensic data. As digital signatures become a standard, laboratories must remain vigilant in implementing security practices to protect sensitive genetic information. Future developments will likely focus on enhancing detection methods and extending protections to legacy systems.

The Hacker News Tags:Applied Biosystems, CVE-2026-17583, Cybersecurity, data integrity, data tampering, digital signatures, DNA security, forensic analysis, software update, Thermo Fisher

Post navigation

Previous Post: N-Able N-Central Flaw Grants Full Access to RMM Console
Next Post: Russian APT Targets Public Wi-Fi in Credential Theft Campaign

Related Posts

Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits The Hacker News
Google Unveils Gemini 3.5 Flash Cyber AI for Software Security Google Unveils Gemini 3.5 Flash Cyber AI for Software Security The Hacker News
Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code The Hacker News
A New Approach to a Decade-Old Challenge A New Approach to a Decade-Old Challenge The Hacker News
SysAid Flaws Under Active Attack Enable Remote File Access and SSRF SysAid Flaws Under Active Attack Enable Remote File Access and SSRF The Hacker News
Critical Vulnerability in Cursor Allows Windows Code Execution Critical Vulnerability in Cursor Allows Windows Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks
  • XCSSET v40 Targets macOS Devs via Compromised Xcode
  • Cyberattacks on US Water Systems Linked to Iran

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks
  • XCSSET v40 Targets macOS Devs via Compromised Xcode
  • Cyberattacks on US Water Systems Linked to Iran

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark