Researchers from Microsoft and partner organizations have identified a critical vulnerability in current biosecurity screening systems used by DNA synthesis companies. These systems are designed to prevent the synthesis of DNA sequences that could be used to create dangerous toxins or pathogens by scanning orders for known threat sequences. However, advances in AI-assisted protein engineering have enabled the design of novel proteins, including modified versions of known toxins such as ricin, that can evade these traditional screening methods. In confidential studies, AI protein design (AIPD) tools were shown to generate protein sequences that, while functionally similar to known toxins, were sufficiently different at the DNA level to bypass existing biosecurity checks. This discovery has been likened to a 'biological zero-day,' representing an unrecognized and unmitigated security gap in the biosecurity infrastructure. The research team conducted a two-year project, including a 10-month confidential collaboration with stakeholders across sectors, to develop and test new 'red-teaming' methods for identifying and addressing these vulnerabilities. Their work culminated in the development of practical 'patches'—enhanced screening protocols and tools—that have now been adopted globally to make DNA synthesis screening more resilient against AI-generated threats. The findings highlight the dual-use nature of AI in biology, where the same technologies that promise breakthroughs in medicine and materials science can also be misused to create novel biological threats. The researchers' approach drew on methodologies from the cybersecurity community, adapting them to the unique challenges of biosecurity. The study, published in Science, underscores the urgent need for ongoing vigilance and adaptation of biosecurity measures as AI capabilities continue to evolve. The incident demonstrates that as AI tools become more sophisticated, traditional security controls may become obsolete unless they are continuously updated. The research also emphasizes the importance of cross-sector collaboration in identifying and mitigating emerging threats. The global adoption of the new screening measures represents a significant step forward in biosecurity, but the researchers caution that the threat landscape will continue to change. The case serves as a warning that AI-driven innovation in biology must be matched by equally innovative security practices. The work also raises broader questions about the governance and oversight of dual-use technologies in the life sciences. The researchers advocate for ongoing research, transparency, and international cooperation to ensure that the benefits of AI in biology are realized safely. The incident has prompted renewed discussion among policymakers, industry, and the scientific community about the adequacy of current biosecurity frameworks. The study's impact is already being felt, with DNA synthesis companies worldwide updating their protocols to address the newly identified risks. The episode illustrates the growing intersection of cybersecurity and biosecurity in the age of AI.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Media coverage and public commentary in early October 2025 drew broader attention to the risk that AI-designed proteins could bypass threat-screening tools. The reporting framed the issue as a potential new biosecurity vulnerability created by advances in generative biology tools.
By the time of public disclosure, the researchers and IBBIS had established a tiered-access framework to control access to sensitive methods and data, using access requests, information tiers, and usage agreements. Science leadership formally endorsed the approach, and Microsoft provided an endowment to help sustain the program.
On October 2, 2025, the paper "Strengthening nucleic acid biosecurity screening against generative protein design tools" was published in Science. It reported computer-based studies showing AI-assisted protein design could generate modified proteins of concern, such as ricin variants, that might evade DNA synthesis screening systems.
Over a 10-month collaboration, researchers and cross-sector partners created biosecurity red-teaming methods and screening updates to address gaps exposed by AI-designed proteins. The resulting patches were adopted globally before the findings were publicly disclosed.
Researchers began a confidential, two-year effort in late 2023 to study whether AI-assisted protein design could create harmful proteins that evade existing biosecurity screening systems. The work was kept nonpublic initially to reduce information-hazard risks while mitigations were developed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.