CubePilot Drone Software – Hit by DNS Hijacking

Overview

Australian drone flight controller developer CubePilot has confirmed a severe DNS hijacking attack that disrupted operations and exposed users to credential theft and potential malware delivery. The incident occurred on July 24, 2026, when attackers gained control of the cubepilot[.]org domain DNS settings, redirecting traffic to attacker‑controlled infrastructure.

What Happened

  • DNS hijacking allowed attackers to intercept traffic intended for CubePilot’s internal systems.
  • Fraudulent TLS certificates were issued, covering all cubepilot.org subdomains.
  • Users visiting CubePilot services saw valid HTTPS connections, unknowingly landing on attacker infrastructure.
  • Credentials entered on CubePilot’s portal and forum during July 24 may have been captured.

CubePilot warned: “If you used the same password anywhere else, change it there now.”

CubePilot’s Response

  • Regained control of domains and revoked fraudulent certificates.
  • Preserved forensic evidence and notified providers.
  • Reported the incident to the Australian Cyber Security Centre and law enforcement.
  • Took OEM services, community forum, documentation portal, and ERP portal offline as a precaution.
  • Advised customers not to flash firmware downloaded on July 24–25 until integrity checks are complete. Firmware obtained before July 24 is considered safe.

Risks to Users

  • Credential theft — usernames, passwords, and sensitive data may have been intercepted.
  • Firmware tampering — potential compromise of drone autopilot software.
  • Phishing and payment fraud — attackers may send fake payment requests.
  • Defense and government exposure — CubePilot’s UAV products are used in agriculture, rescue, and defense, including deliveries to Ukraine.

Defensive Guidance

CubePilot advises:

  • Change reused passwords immediately.
  • Verify payment requests by phone with usual contacts.
  • Avoid flashing firmware downloaded on July 24–25 until safety checks are complete.
  • Monitor accounts for suspicious activity.

Expert in the Cloud Insight

This incident underscores how DNS hijacking remains one of the most dangerous attack vectors. By combining domain control with fraudulent TLS certificates, attackers can seamlessly impersonate trusted services. For enterprises, the lesson is clear: DNS security and certificate monitoring are mission‑critical, especially for companies whose products intersect with defense, government, and critical infrastructure.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.