"The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured — the portal and the forum included," CubePilot wrote in a status update.
DNS hijacking and stolen TLS certificates
CubePilot, an Australian company that designs flight controllers for unmanned aerial vehicles, reported that an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing traffic destined for CubePilot’s internal services to be redirected to attacker-controlled infrastructure, according to a status update published on the company’s website. The attacker also obtained TLS certificates covering all cubepilot.org subdomains, meaning visitors would have seen valid HTTPS connections while unknowingly communicating with the adversary’s systems.
Operational impact on CubePilot services and portals
As a result of the incident, CubePilot says multiple public services are offline. The company confirmed that all OEM services, the community forum, and the documentation portal are currently unavailable. CubePilot’s CEO, Philip Rowse, stated on LinkedIn that the company’s ERP portal has been taken offline as a precaution while an investigation is underway.
Company response: containment, evidence preservation and reporting
CubePilot reported regaining control of its domains on July 24, revoking the fraudulently issued certificates and preserving evidence tied to the incident. The company notified relevant providers and reported the intrusion to the Australian Cyber Security Centre and law enforcement, and it pledged to notify affected entities directly where impact is confirmed through its ongoing investigation.
Risks to users, firmware guidance, and payment-fraud warning
The company explicitly warned that credentials entered on affected services during July 24 may have been captured, and advised: “If you used the same password anywhere else, change it there now.” CubePilot also cautioned customers and users about firmware files: it is evaluating the integrity of published firmware images and advised users not to flash images downloaded on July 24–25 until checks confirm their safety. According to the company, firmware obtained before July 24 is currently considered safe to use.
In addition, CubePilot warned clients that any payment requests claiming to be from CubePilot should not be acted on without phone confirmation with their usual contact.
What this means for CubePilot customers, UAV operators, and security teams
- CubePilot customers: Expect direct notifications where the company’s investigation confirms impact; follow CubePilot’s explicit guidance to change reused passwords and to verify any payment requests by phone.
- UAV operators and integrators: Avoid flashing firmware images downloaded on July 24–25 until CubePilot completes its checks; images obtained before July 24 are regarded by the company as safe.
- Security teams and incident responders: The incident demonstrates how DNS control plus valid TLS certificates can enable credential capture even over HTTPS. CubePilot reported revoking fraudulent certificates and notifying providers; security teams connected to affected integrations will need to confirm whether credentials or downloads were exposed and to coordinate with CubePilot as the company notifies impacted entities.
CubePilot’s products include “autopilots” and navigation hardware for UAVs used in surveying, search and rescue, agriculture, and for defense and government applications. The company has also publicly announced support for Ukraine, and its products have been delivered there, including as part of an Australian government assistance package—placing some users of its hardware among the potential audiences for the company’s notifications.
The immediate facts are straightforward: DNS records for cubepilot[.]org were altered on July 24, TLS certificates for every subdomain were obtained by the attacker, multiple public services remain offline while CubePilot investigates, and the company has taken steps to regain control, revoke certificates, preserve evidence and inform authorities. The critical outstanding questions are procedural and forensic: which credentials were actually harvested, whether any firmware was altered, and which external parties will require direct notification as the investigation proceeds.
Original report: https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/




