Skip to content
CubePilot hit by DNS hijacking attack, warns of potential credential theft

CubePilot hit by DNS hijacking attack, warns of potential credential theft

Feeds.Feedburner •SC Staff • July 29, 2026

CubePilot, an Australian firm specializing in flight controllers for drones, has experienced a significant operational disruption due to a DNS hijacking attack. The incident allowed attackers to redirect traffic and potentially intercept sensitive data. All OEM services, the community forum, and the documentation portal are currently offline as a precautionary measure while an investigation is underway, as reported by Bleeping Computer.

The attack, which occurred on July 24, involved an unauthorized individual gaining control of CubePilot's cubepilot[.]org domain DNS settings. This enabled the attacker to intercept traffic intended for internal systems and obtain TLS certificates for all subdomains. Consequently, users visiting CubePilot's services on that day might have unknowingly connected to attacker-controlled infrastructure, potentially exposing credentials entered on the portal and forum.

CubePilot regained control of its domains on July 24, revoked the fraudulent certificates, and reported the incident to authorities. The company is currently evaluating the integrity of published firmware images and advises customers not to flash any downloaded between July 24-25 until safety checks are complete. Firmware obtained before July 24 is considered safe. CubePilot designs autopilots and hardware for UAVs used in various sectors, including surveying, and rescue, agriculture, defense, and government applications.

Source: Bleeping Computer

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)

Industries (1)