Drone Flight Controller Firm CubePilot Hit by DNS Hijacking Attack
Australian firm **CubePilot**, a leading designer of flight controllers for Uncrewed Aerial Vehicles (UAVs), has disclosed a significant operational disruption stemming from a sophisticated DNS hijacking attack. Threat actors successfully rerouted legitimate traffic and obtained TLS certificates, potentially compromising user credentials and raising concerns about firmware integrity.

**CubePilot**, an Australian company specializing in flight controllers for drones, has reported a severe operational disruption due to a DNS hijacking incident. This type of attack allows malicious actors to redirect users to their own infrastructure, diverting traffic intended for legitimate services.
### Attack Details and Impact
According to a status update from **CubePilot**, the attackers gained control of the `cubepilot[.]org` domain's DNS settings on July 24. This enabled them to intercept traffic destined for the company's internal systems.
Critically, the attackers also managed to obtain TLS certificates for all `cubepilot.org` subdomains. This meant that users visiting affected services would have observed valid HTTPS connections, unaware that they were interacting with attacker-controlled infrastructure. This setup significantly increases the risk of data interception.
**CubePilot** warned, "The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured β the portal and the forum included."
Users who may have reused passwords across different services were strongly advised to change them immediately.
### Response and Ongoing Investigation
**CubePilot** confirmed that it regained control of its domains on July 24. Subsequent actions included revoking the fraudulently issued certificates, preserving forensic evidence, notifying relevant providers, and reporting the incident to the **Australian Cyber Security Centre** and law enforcement agencies.
The company has committed to directly notifying any affected entities once the full scope of impact is confirmed through its ongoing investigation.
### Operational Status and Firmware Concerns
**CubePilot**'s products, including autopilots and navigation hardware, are utilized in various critical applications such as surveying, search and rescue, agriculture, and even defense and government sectors. The company has previously supplied its products as part of Australian government assistance packages.
Currently, all OEM services, the community forum, and the documentation portal remain offline as a precautionary measure. **Philip Rowse**, **CubePilot**'s CEO, also confirmed on LinkedIn that the platform's ERP portal has been taken offline while the investigation progresses.
A significant concern is the integrity of published firmware images. **CubePilot** is actively evaluating them and has advised users against flashing any images downloaded on July 24-25 until safety checks are completed. Firmware obtained before July 24 is currently considered safe.
Furthermore, clients receiving payment requests purportedly from **CubePilot** are urged to verify them directly via phone with their usual contacts before taking any action.