Vulnerability Management

Critical vulnerability in DNA forensic software could compromise 30 years of evidence

Based on information from Tech Radar, researchers have uncovered a critical vulnerability in forensic software used by major US crime labs, potentially allowing for the undetectable modification of DNA evidence.

A group of forensic and computer scientists discovered that an AI model can be used to undetectably alter digital scans of DNA evidence created since 1995. While Thermo Fisher Scientific, the software provider, stated there are no known instances of exploitation, researchers confirmed they could not find a way to detect tampering. A systems engineer reportedly exploited the vulnerability in under an hour, even accessing encrypted files. The potential for malicious actors to add or remove DNA profiles could lead to wrongful convictions or acquittals.

Experts note that forensic science has lagged in adopting security measures from other industries, leading to a patchwork of security across over 200 labs. Thermo Fisher Scientific has acknowledged the issue and is implementing a software update with digital signatures to help verify data integrity moving forward.

Source: Tech Radar

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds