Skip to main content
EPSS 0.2%top 89%

Researchers altered a forensic DNA evidence file in 45 minutes and the analysis software raised no warning (CVE-2026-17583)

0
High
Published: 08/05/2026 (08/05/2026, 20:23:32 UTC)
Source: Reddit Cybersecurity

Description

CVE-2026-17583 is a vulnerability in Thermo Fisher's Applied Biosystems human identification instruments where forensic DNA evidence files (.fsa and .hid) can be altered between creation and analysis without detection. Researchers demonstrated that these files could be modified in about 45 minutes to merge DNA profiles into a single file that appears unaltered since 2015. Thermo Fisher issued an update adding digital signatures to files created after the patch, but no retroactive validation exists for older files, and some end-of-life products do not receive updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering.

Reddit Discussion

r/cybersecurity·posted by u/godShadyy
00

Disclosure: I write a daily security newsletter, this was today's issue. The

substance is below, link at the end.

Thermo Fisher's July 31 bulletin covers CVE-2026-17583 (CVSS v4.0 8.2). The

.fsa and .hid files from Applied Biosystems human identification instruments can

be modified between the instrument writing them and the analysis software

loading them, and the change is nearly undetectable. Nothing in the file let the

software confirm the bytes were the ones the instrument wrote. Nathan Adams of

Forensic Bioinformatics told the WSJ his first successful modification took

about 45 minutes, merging scans from two DNA profiles into one file that

presented as untouched since 2015.

The updates add digital signatures, which only protects files written after the

upgrade. The bulletin does not address retroactive validation, the researchers

found no way to detect prior tampering, and these file types have been produced

since 1995. Three end-of-life product lines get no update at all.

Full writeup with the affected versions and remediation order:

https://www.linkedin.com/pulse/researchers-altered-dna-evidence-file-45-minutes-tymoteusz-netter-bxhhf/

Bulletin:

https://documents.thermofisher.com/TFS-Assets/CORP/Product-Guides/fsa_hid_bulletin.pdf

Most of us have outputs a downstream process treats as authoritative without

checking provenance. For files predating any signing mechanism, write-access

logs on the landing directory are the only retrospective evidence I can build.

What are you using?

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 12:56:55 UTC

Technical Analysis

The vulnerability CVE-2026-17583 affects forensic DNA evidence files (.fsa and .hid) generated by Thermo Fisher's Applied Biosystems human identification instruments. The files can be modified after being written by the instrument but before being loaded by the analysis software, without any warning or detection. Researchers showed that it is possible to merge DNA profiles into a single file that appears authentic and unchanged since 2015. Thermo Fisher's bulletin states that digital signatures have been added to files written after the update to prevent tampering, but no mechanism exists to validate files created before the update. Additionally, some end-of-life products will not receive updates, leaving older forensic evidence files vulnerable to undetected manipulation.

Potential Impact

The vulnerability allows undetectable tampering with forensic DNA evidence files, potentially compromising the integrity of forensic evidence used in legal and investigative contexts. Modified files can merge multiple DNA profiles into one, misleading analysis results without raising any software warnings. The lack of retroactive validation and absence of updates for some end-of-life products means that historical forensic evidence remains at risk, which could undermine trust in forensic processes and outcomes.

Mitigation Recommendations

Thermo Fisher has issued a bulletin implementing digital signatures on forensic DNA evidence files created after the update, which protects new files from tampering. However, no retroactive validation exists for files created prior to the update, and some end-of-life products will not receive patches. Users should apply the update to supported products to ensure new files are protected. For older files, no technical mitigation is currently available; organizations should consider additional procedural controls such as maintaining strict write-access logs and chain-of-custody documentation to detect potential tampering retrospectively.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":56,"reasons":["external_link","newsworthy_keywords:cve-,analysis","security_identifier","established_author","recent_news"],"isNewsworthy":true,"foundNewsworthy":["cve-","analysis"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a7219a2bf8831d539238d1c

Added to database: 08/04/2026, 16:56:02 UTC

Last enriched: 08/12/2026, 12:56:55 UTC

Last updated: 09/17/2026, 10:01:29 UTC

Views: 168

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses