CubePilot Faces DNS Hijacking, Potential Credential Theft

CubePilot Faces DNS Hijacking, Potential Credential Theft

First seen 29 Jul 2026, 01:13 UTC Bleepingcomputercubepilot.comFeeds.Feedburnerwww.tines.com 83% similarity 69.0

Article Content

Browse articles
ThreatCluster

On July 24, 2026, CubePilot, an Australian drone software developer, suffered a DNS hijacking attack that allowed an unauthorized party to intercept traffic intended for its internal systems. The attacker gained control of the cubepilot.org domain DNS settings and obtained TLS certificates for all subdomains, exposing users to potential credential theft. CubePilot has since taken its services offline for verification, advising users to change passwords if they entered them on the affected services during the attack. The company regained control of its domains the same day, revoked the fraudulent certificates, and reported the incident to the Australian Cyber Security Centre and law enforcement. Currently, all OEM services, the community forum, and the documentation portal remain offline while investigations are ongoing. Users are cautioned against flashing firmware downloaded between July 24-25 until safety checks are completed.

Key Points: • CubePilot experienced a DNS hijacking attack on July 24, 2026. • The attacker intercepted traffic and potentially captured user credentials. • All CubePilot services are offline while the company investigates the incident.

ThreatCluster AI How this analysis works

Timeline

2026-07-24
DNS hijacking attack occurred
An unauthorized party gained control of CubePilot's DNS settings, intercepting traffic and obtaining TLS certificates.
Bleepingcomputer
2026-07-24
CubePilot regained control of domains
CubePilot restored its domain control and revoked the fraudulent certificates on the same day of the attack.
cubepilot.com
2026-07-24
Services taken offline
All OEM services, the community forum, and documentation portal were taken offline for verification following the attack.
Bleepingcomputer
2026-07-29
Security notice published
CubePilot issued a security notice detailing the attack and advising users on password changes and firmware safety checks.
cubepilot.com

Community

Browse all →

Tracked Entities in This Story