AI Security AI安全 20h ago Updated 15h ago 更新于 15小时前 41

Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable 赛默飞修复可能导致DNA文件篡改几乎无法检测的漏洞

Thermo Fisher Scientific patched CVE-2026-17583, a High-severity (CVSS 8.2) vulnerability in Applied Biosystems human identification software that could allow nearly undetectable tampering of .fsa and .hid DNA data files before analysis The fix adds digital signatures to five supported product lines, enabling verification that files have not been altered; three end-of-life products will receive no update Researchers demonstrated the flaw by using Anthropic's Claude to merge two DNA profiles into Thermo Fisher Scientific修复了Applied Biosystems人类识别软件中的高危漏洞(CVE-2026-17583,CVSS v4.0评分8.2),该漏洞允许在分析软件加载前篡改DNA数据文件 修复方案为五个受影响产品系列添加数字签名验证机制,但三个已停止支持(EOL)的产品线将无更新 研究人员利用Claude AI在45分钟内成功演示了几乎无法检测的文件篡改,攻击者需具备实验室服务器访问权限 漏洞可能自1995年以来就存在于数字DNA记录中,且无法检测历史篡改,对法医证据完整性构成严重威胁

55
Hot 热度
65
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Thermo Fisher Scientific patched CVE-2026-17583, a High-severity (CVSS 8.2) vulnerability in Applied Biosystems human identification software that could allow nearly undetectable tampering of .fsa and .hid DNA data files before analysis
  • The fix adds digital signatures to five supported product lines, enabling verification that files have not been altered; three end-of-life products will receive no update
  • Researchers demonstrated the flaw by using Anthropic's Claude to merge two DNA profiles into a single file that appeared authentic and undated since 2015, with no warnings from standard analysis software
  • Exploitation requires local or remote server access and knowledge of DNA testing workflows; no known instances of exploitation have been reported as of August 2026
  • The vulnerability likely affects digital DNA records produced since 1995, and there is currently no known method to detect whether prior tampering occurred on historical files

Why It Matters

This vulnerability strikes at the integrity of forensic DNA evidence used in criminal justice systems worldwide, raising serious concerns about the reliability of digital records in court-admissible testing. For AI and security practitioners, it demonstrates how generative AI tools like Claude can lower the barrier for crafting sophisticated, undetectable data manipulations in specialized scientific domains. The case also highlights the growing intersection of cybersecurity, digital forensics, and biometric data integrity as critical infrastructure.

Technical Details

  • Vulnerability: CVE-2026-17583, CVSS v4.0 score of 8.2 (High), affecting .fsa and .hid file outputs from Applied Biosystems DNA analysis instruments; files could be modified before analysis software loads them without triggering detection
  • Fix: Digital signatures implemented across five product lines (3500/3500xL Series Data Collection Software 4.0.3, 3730/3730xL Series 5.0.3, SeqStudio Genetic Analyzer 1.2.6, SeqStudio Flex 1.2.1, GeneMapper ID-X v1.7.4); three end-of-life products (3130 Series 4.1 and earlier, ABI PRISM 3100/3100-Avant 2.0 and earlier, ABI PRISM 310 3.1 and earlier) receive no patch
  • Proof of concept: Researcher Nathan Adams used Anthropic's Claude to generate code that merged two DNA profiles into a single .fsa file appearing unaltered since 2015, passing validation in standard laboratory analysis software with no warnings
  • Disclosure: Identified by Nathan Adams, Kevin Dyer, and Laura Gaydosh Combs in coordination with CISA; disclosed via Thermo Fisher's July 31 security bulletin
  • Limitations: The bulletin does not address retroactive validation of pre-patch files, and researchers reported no known method to detect whether historical tampering occurred on files dating back to 1995

Industry Insight

  • Forensic laboratories and legal institutions should prioritize patching affected Applied Biosystems products immediately and implement strict chain-of-custody and access-control measures for any systems that cannot be updated, as undetected DNA file tampering could have irreversible consequences for ongoing and past cases
  • This incident underscores the need for digital signature and integrity verification standards across all scientific data pipelines, especially in regulated industries where AI-assisted data manipulation is becoming increasingly accessible and affordable
  • Organizations should treat the 1995-onward historical data gap as a known risk factor; while retroactive detection may not be feasible, establishing baseline integrity controls going forward and auditing high-risk cases with independent verification can mitigate exposure

TL;DR

  • Thermo Fisher Scientific修复了Applied Biosystems人类识别软件中的高危漏洞(CVE-2026-17583,CVSS v4.0评分8.2),该漏洞允许在分析软件加载前篡改DNA数据文件
  • 修复方案为五个受影响产品系列添加数字签名验证机制,但三个已停止支持(EOL)的产品线将无更新
  • 研究人员利用Claude AI在45分钟内成功演示了几乎无法检测的文件篡改,攻击者需具备实验室服务器访问权限
  • 漏洞可能自1995年以来就存在于数字DNA记录中,且无法检测历史篡改,对法医证据完整性构成严重威胁

为什么值得看

该漏洞直接威胁法医DNA证据的数字完整性,篡改后的文件在分析软件中不会触发任何警告,可能影响司法判决。对于依赖DNA数据的法医实验室、司法鉴定机构和生物识别安全从业者而言,这是一个需要立即响应的严重安全问题。

技术解析

  • 漏洞机制:.fsa和.hid格式的输出文件在加载到分析软件前可被修改,缺乏数字签名验证导致篡改几乎无法检测
  • 修复方案:五个产品系列(3500/3500xL、3730/3730xL、SeqStudio、SeqStudio Flex、GeneMapper ID-X)已发布更新添加数字签名,但三个EOL产品(3130 Series、ABI PRISM 3100/3100-Avant、ABI PRISM 310)无更新
  • 攻击演示:研究人员Nathan Adams使用Claude AI结合两个DNA谱图生成伪造文件,文件显示为2015年未修改状态,在多个实验室使用的分析软件中未触发警告
  • 访问要求:攻击者需要本地或远程访问实验室服务器,并具备DNA测试工作原理的专业知识
  • 历史影响:漏洞可能影响自1995年以来生产的数字DNA记录,且无法追溯检测已发生的篡改

行业启示

  • 法医科学领域亟需建立数字证据的端到端完整性验证机制,建议实验室立即实施文件保管链管理、加密存储、最小权限控制和网络隔离等补偿性控制措施
  • 关键基础设施供应商应优先采用数字签名和零信任架构,避免类似"加载前可篡改"的安全设计缺陷
  • 对于无法更新的遗留系统,需制定明确的迁移计划或物理隔离方案,同时评估历史数据的潜在风险

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全