Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Researchers have discovered a serious security flaw in the Illumina iSeq 100 DNA sequencers
Global Security

Researchers have discovered a serious security flaw in the Illumina iSeq 100 DNA sequencers

AdminBy AdminJanuary 7, 2025No Comments3 Mins Read
DNA Sequencers
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


January 7, 2025Ravi LakshmananFirmware Security / Malware

DNA sequencers

Cybersecurity researchers have discovered firmware security vulnerabilities in the Illumina iSeq 100 DNA sequencing instrument that, if successfully exploited, could allow attackers to block or install persistent malware on sensitive devices.

“The Illumina iSeq 100 used a very outdated implementation BIOS firmware using CSM (Compatibility Support Mode) mode and without secure boot or standard firmware write protection,” Eclypsium said in a report shared with The Hacker News.

“This would allow an attacker on the system to overwrite the system’s firmware to either ‘brick’ the device or install a firmware implant for the attacker’s permanent persistence.”

Cyber ​​security

While the Unified Extensible Firmware Interface (UEFI) is a modern replacement for the Basic Input/Output System (BIOS), the firmware security company reported that the iSeq 100 boots with an old BIOS version (B480AM12 – 04/12/2018) that has known vulnerabilities.

Also conspicuously absent are safeguards that tell the hardware where it can read and write firmware, allowing an attacker to modify the device’s firmware. Secure Boot is also not enabled, allowing malicious firmware changes to go undetected.

DNA sequencers

Eclypsium noted that it is not recommended for new high-value assets to support CSM, as it is mainly intended for older devices that cannot be upgraded and must maintain compatibility. After the responsible disclosure, Illumina released a fix.

In a hypothetical attack scenario, an adversary could target unpatched Illumina devices, elevate their privileges, and write arbitrary code to the firmware.

This is not the first time that serious vulnerabilities have been discovered in Illumina’s DNA gene sequencers. In April 2023 critical security flaw (CVE-2023-1968CVSS score: 10.0) could make it possible to eavesdrop on network traffic and remotely transmit arbitrary commands.

Cyber ​​security

“The ability to overwrite the firmware on the iSeq 100 would allow attackers to easily disable the device, causing significant disruption in the context of a ransomware attack. Not only would this disable a valuable device, but it would also likely take considerable effort to recover the device by manually flashing the firmware,” Eclypsium said.

“This can significantly raise the stakes in the context of ransomware or cyber attacks. Sequencers are important for the detection of genetic diseases, cancer, the identification of drug-resistant bacteria and for the production of vaccines. This would make these devices a ripe target for the state. established actors with geopolitical motives in addition to the more traditional financial motives of ransomware actors.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025

Meta adds support to logy for Android and iOS users

June 19, 2025

Linux’s new drawbacks provide complete root access via PAM and Udisks in major distributions

June 19, 2025

The new malicious company uses Cloudflare tunnels to deliver rats through phishing networks

June 18, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.