The software most American crime labs use to read DNA evidence carried a flaw. It let someone with the right access quietly rewrite the results, and leave almost no trace. AI made the attack easy. Thermo Fisher Scientific has now patched it. But the fix only guards files created from here on.
The weakness sits in several Applied Biosystems tools that turn a DNA sample into a digital file. The company’s security bulletin says an attacker could alter the .fsa and .hid files those machines produce before analysis software loads them. That works only if someone first bypasses a lab’s controls. The flaw carries the identifier CVE-2026-17583 and a high severity score of 8.2.
What makes it striking is how little skill it now takes. Nathan Adams, an engineer at Forensic Bioinformatics, wrote his first working edit with Anthropic’s Claude in about 45 minutes. He told the Wall Street Journal how quickly it went. His code stitched two people’s DNA profiles into one file. It looked untouched since 2015, and raised no warning in software many labs rely on.
The scope is what unsettles forensic scientists. The researchers believe the weakness has sat in these files since 1995. That covers roughly 30 years of casework, The Hacker News reported. They also say they found no way to tell whether anyone altered a past file. The flaw hits the digital records, not the physical DNA samples.










