Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Critical vulnerability in DNA forensic software could compromise 30 years of evidence

A critical vulnerability in forensic DNA analysis software allows an AI model to undetectably alter digital DNA evidence scans dating back to 1995, potentially compromising case integrity. The article does not provide a CVSS score, specific affected version ranges, a fixed version, or a workaround.
Read Full Article →

Vulnerability Management Critical vulnerability in DNA forensic software could compromise 30 years of evidence August 4, 2026 Share By SC Staff Based on information from Tech Radar, researchers have uncovered a critical vulnerability in forensic software used by major US crime labs, potentially allowing for the undetectable modification of DNA evidence. A group of forensic and computer scientists discovered that an AI model can be used to undetectably alter digital scans of DNA evidence created since 1995. While Thermo Fisher Scientific, the software provider, stated there are no known instances of exploitation, researchers confirmed they could not find a way to detect tampering. A systems engineer reportedly exploited the vulnerability in under an hour, even accessing encrypted files. The potential for malicious actors to add or remove DNA profiles could lead to wrongful convictions or acquittals. Experts note that forensic science has lagged in adopting security measures from other industries, leading to a patchwork of security across over 200 labs. Thermo Fisher Scientific has acknowledged the issue and is implementing a software update with digital signatures to help verify data integrity moving forward. Source: Tech Radar SC Staff Related Vulnerability Management Dataminr report: attackers exploit vulnerabilities faster than organizations patch SC Staff August 4, 2026 Dataminr's 2026 Mid-Year Threat Landscape Report reveals that the median time to patch vulnerabilities has increased to 43 days, contrasting sharply with the average attacker breakout time of just 29 minutes. Vulnerability Management N-able addresses critical N-central vulnerabilities exploited by attackers SC Staff August 3, 2026 Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrative access to N-central servers. Vulnerability Management Critical vulnerability in Rails Active Storage could lead to RCE SC Staff August 3, 2026 The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article