← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

CubePilot drone software developer suffers DNS hijacking attack, user credentials potentially exposed

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CubePilot's cubepilot.org domain DNS settings were hijacked on July 24.
  • Attacker obtained TLS certificates for all cubepilot.org subdomains.
  • User credentials entered on July 24 may have been compromised.
  • Firmware downloaded on July 24-25 is under evaluation for integrity.

DNS Hijacking Incident

On July 24, CubePilot, an Australian company specializing in drone flight controllers, reported a severe operational disruption due to a DNS hijacking attack. The attacker gained control of the cubepilot.org domain's DNS settings, enabling them to redirect traffic intended for CubePilot's internal systems to their own infrastructure.

Credential and Data Exposure Risk

The attacker also acquired TLS certificates for all cubepilot.org subdomains. This meant users visiting affected services would have seen valid HTTPS connections while unknowingly interacting with attacker-controlled systems. CubePilot warned that credentials entered on any of its services, including the portal and forum, on July 24 may have been compromised. The company advised users to change passwords if they reused them on other platforms.

Company Response and Mitigation

CubePilot regained control of its domains on July 24, revoked the fraudulently issued certificates, and preserved evidence of the attack. The incident was reported to the Australian Cyber Security Centre and law enforcement. The company plans to directly notify affected entities once its investigation confirms impact. As a precautionary measure, all OEM services, the community forum, documentation portal, and the ERP portal have been taken offline.

Firmware Integrity Concerns

CubePilot is currently evaluating the integrity of firmware images published during the incident. The company advised users not to flash any firmware downloaded on July 24-25 until safety checks are completed. Firmware obtained before July 24 is considered safe for use.

Background and Impact

CubePilot designs autopilots and navigation hardware for UAVs used in various sectors, including surveying, search and rescue, agriculture, defense, and government. The company had previously announced support for Ukraine, with its products being delivered there as part of an Australian government assistance package. The disruption affects critical services for its users and raises concerns about the supply chain integrity for drone components.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

CubePilot, an Australian firm developing flight controllers for drones, experienced a DNS hijacking attack on July 24, allowing an attacker to intercept traffic and obtain TLS certificates for its subdomains. This incident potentially exposed user credentials entered on CubePilot services and led to the company taking several services offline for investigation.