CubePilot Faces DNS Hijacking Attack, User Credentials Compromised

CubePilot Faces DNS Hijacking Attack, User Credentials Compromised

First seen 29 Jul 2026, 01:13 UTC Bleepingcomputercubepilot.com 74% similarity 70.5

Article Content

Browse articles
ThreatCluster

On July 24, 2026, CubePilot's DNS for cubepilot.org was hijacked, allowing an unauthorized party to intercept traffic to internal systems. The attacker gained control of DNS settings and TLS certificates, potentially capturing user credentials entered on the site. CubePilot took immediate action by taking affected services offline and revoking fraudulent certificates. They reported the incident to the Australian Cyber Security Centre and law enforcement. Users are advised to change passwords if they reused them elsewhere and to avoid flashing firmware downloaded during the attack window. The company is currently verifying the integrity of its published firmware images. Email services on cubepilot.com remain unaffected, and updates will be posted on their security notice page.

Key Points: • CubePilot's DNS was hijacked on July 24, 2026, leading to potential credential theft. • The attacker gained control of TLS certificates, allowing for deceptive HTTPS connections. • Affected services are offline while CubePilot investigates and verifies system integrity.

ThreatCluster AI How this analysis works

Timeline

2026-07-24
DNS hijacking incident occurred
An unauthorized party gained control of CubePilot's DNS settings, intercepting user traffic and potentially capturing credentials.
BleepingComputer
2026-07-24
Fraudulent certificates obtained
The attacker acquired TLS certificates for all cubepilot.org subdomains, enabling secure but deceptive connections.
BleepingComputer
2026-07-24
CubePilot regained control of domains
CubePilot restored control of their domains and revoked the fraudulent certificates on the same day of the attack.
cubepilot.com
2026-07-29
Security notice published
CubePilot issued a security notice detailing the incident and advising users on password changes and firmware verification.
cubepilot.com

Community

Browse all →

Tracked Entities in This Story