Bleepingcomputer
CubePilot Faces DNS Hijacking Attack, User Credentials Compromised
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 24, 2026, CubePilot's DNS for cubepilot.org was hijacked, allowing an unauthorized party to intercept traffic to internal systems. The attacker gained control of DNS settings and TLS certificates, potentially capturing user credentials entered on the site. CubePilot took immediate action by taking affected services offline and revoking fraudulent certificates. They reported the incident to the Australian Cyber Security Centre and law enforcement. Users are advised to change passwords if they reused them elsewhere and to avoid flashing firmware downloaded during the attack window. The company is currently verifying the integrity of its published firmware images. Email services on cubepilot.com remain unaffected, and updates will be posted on their security notice page.
Key Points: • CubePilot's DNS was hijacked on July 24, 2026, leading to potential credential theft. • The attacker gained control of TLS certificates, allowing for deceptive HTTPS connections. • Affected services are offline while CubePilot investigates and verifies system integrity.