CubePilot drone software dev hit by DNS hijacking to intercept traffic

A severe DNS hijacking attack has struck CubePilot, an Australian firm that designs flight controllers for drones (UAVs), crippling its operations and potentially exposing sensitive data to interception. The incident highlights the vulnerability of domain name system (DNS) records to tampering, which can have far-reaching consequences for users.

The attacker exploited the DNS settings for cubepilot[.]org on July 24, allowing them to redirect traffic intended for internal systems. This maneuver enabled the attackers to obtain Transport Layer Security (TLS) certificates covering all cubepilot.org subdomains, making it appear as though users were accessing legitimate services even when they landed on attacker-controlled infrastructure. As a result, sensitive data, such as credentials entered on CubePilot’s portal and forum, may have been intercepted by the attackers.

CubePilot has acknowledged that users who visited affected services between July 24 and July 25 may be at risk of having their sensitive information compromised. The company has taken immediate action to regain control of its domains, revoke the fraudulently issued certificates, and notify relevant providers and law enforcement agencies. It has also promised to directly notify affected entities where impact is confirmed through its ongoing investigation.

The incident serves as a stark reminder that even organizations with robust security measures in place can fall victim to sophisticated attacks. CubePilot’s products are used in various sectors, including surveying, search and rescue, agriculture, defense, and government applications. The company has previously demonstrated its commitment to supporting Ukraine, delivering its products to the country as part of an Australian government assistance package.

In light of this incident, it is essential for users to remain vigilant and take necessary precautions to protect themselves from potential threats. CubePilot’s CEO has advised clients not to flash firmware images downloaded on July 24-25 until their safety can be confirmed, and to verify payment requests claiming to be from the company by contacting them directly over the phone.

The incident also underscores the importance of regular security audits and vulnerability assessments to identify and address potential weaknesses in an organization’s defenses. By staying proactive and aware of emerging threats, users can minimize their exposure to attacks like this one and maintain the integrity of their systems and data.


Source: Bleeping Computer — 2026-07-28