AUTO-UPDATED

CubePilot drone software dev hit by DNS hijacking to intercept traffic

Australian drone hardware manufacturer CubePilot suffered a significant DNS hijacking attack on July 24, potentially exposing user credentials and sensitive data across its web portals and community forums.

Key Points

  • Attackers hijacked the cubepilot.org domain and obtained fraudulent TLS certificates to intercept traffic and impersonate legitimate company services.
  • CubePilot has taken its ERP portal, community forum, and documentation services offline while conducting a security investigation.
  • Users are advised to change passwords used on the platform and avoid flashing firmware images downloaded between July 24 and July 25.
  • The company reported the breach to the Australian Cyber Security Centre and law enforcement to assist in the ongoing investigation.
  • Clients should verify any payment requests via telephone to avoid potential fraud resulting from the compromised infrastructure.

Why it Matters

This incident highlights the severe risks posed by DNS hijacking, which can bypass standard browser security warnings through the use of fraudulently obtained TLS certificates. Because CubePilot provides critical navigation hardware for defense and government sectors, the compromise of its internal systems raises significant concerns regarding supply chain security and data integrity.
BleepingComputer Published by Bill Toulas
Read original