24TOPNEWS · ENGLISH

Financial news reader

124 verified events in the selected period.

Page 5 / 5
CompaniesU.S. equities

US forensic DNA analysis files at risk of tampering, Thermo Fisher patches critical flaw

Researchers and forensic experts disclosed a security flaw in digital DNA analysis files used by most US crime labs, potentially allowing undetected tampering with decades of criminal records. The vulnerability dates to 1995 and became easier to exploit with AI code-generation tools. Thermo Fisher Scientific privately acknowledged the issue in July, issued a high-risk advisory last week, and released software with digital signatures. No known malicious exploitation or impact on court rulings has been reported.

A group of forensic and computer experts disclosed that core technology used by the vast majority of crime laboratories across the United States to analyse DNA evidence contains a security vulnerability, leaving a large volume of criminal case files from the past three decades exposed to tampering by hackers. The researchers found that code written with ordinary generative artificial-intelligence software could modify digital data generated from DNA scans without leaving traces. The vulnerability has been hidden in files produced by laboratory equipment since 1995, and the recent rapid evolution of AI technology has significantly lowered the barrier to tampering.

Thermo Fisher Scientific, the main equipment vendor, privately acknowledged the vulnerability in July after receiving the research report and began working on a fix. The company issued a high-risk security advisory last week, warning that if laboratory internal controls were bypassed, the digital files could face "nearly undetectable modification risk," while stressing that no known cases of malicious exploitation had been found. Thermo Fisher said it had cooperated with the US Cybersecurity and Infrastructure Security Agency and released a new software update containing digital-signature functionality to help customers verify data integrity.

The researchers noted that the vulnerability affects only digital analysis files and does not alter the physical DNA samples submitted for testing. In theory, an attacker who gained access to a laboratory server and understood DNA testing principles could fabricate evidence by adding or deleting DNA profiles. Nathan Adams, a systems engineer, used Anthropic's Claude model in tests and managed to modify files in about 45 minutes, even merging two separate DNA profiles into a new file that appeared unaltered, without triggering alerts from the analysis software. There is currently no evidence that the vulnerability has affected rulings in any specific cases.