← Back to Feed

CubePilot drone software dev hit by DNS hijacking to intercept traffic

July 28, 2026 · BleepingComputer · Severity: MEDIUM

CubePilot, an Australian drone flight controller manufacturer, suffered a DNS hijacking attack on July 24, 2026, when an attacker gained control of cubepilot.org DNS settings, intercepting traffic intended for internal systems and fraudulently obtaining TLS certificates for all subdomains. This exposed users to credential theft, malware delivery, and phishing — even on pages showing valid HTTPS. CubePilot regained control of its domains the same day, revoked fraudulently issued certificates, preserved evidence, and reported the incident to the Australian Cyber Security Centre and law enforcement. All OEM services, the community forum, documentation portal, and ERP portal were taken offline pending investigation. The company warned users who entered credentials on July 24 to change passwords immediately, advised against flashing firmware downloaded on July 24–25 until verification is complete, and cautioned clients to verify payment requests over the phone.

Key Takeaways

  • DNS hijacking compromised all subdomains — An attacker gained DNS control over cubepilot.org and fraudulently obtained valid TLS certificates for every subdomain.
  • HTTPS showed valid padlock — Even pages with valid HTTPS certificates were serving attacker content, making phishing nearly undetectable to users.
  • All services taken offline — OEM portal, community forum, documentation, and ERP were disconnected pending investigation.
☕ Buy a Coffee