TechNewsReel
Live

Drone Autopilot Developer CubePilot Hit by DNS Hijacking Attack

Attackers seized control of the company's domain and obtained valid TLS certificates to intercept credentials from UAV operators and defense partners.

TechNewsReel Newsroom · July 29, 2026

Australian UAV flight controller developer CubePilot fell victim to a DNS hijacking attack on July 24, 2026, allowing attackers to intercept traffic to the company's internal systems and capture user credentials.

The attackers gained control of DNS settings for cubepilot.org and used that access to obtain valid TLS certificates for all subdomains. This enabled them to serve legitimate HTTPS connections while routing traffic through malicious infrastructure, leaving users with no browser warnings.

"The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured — the portal and the forum included," CubePilot said in a security notice posted to its website.

Defense and Government Exposure

The incident carries elevated risk because CubePilot's hardware is deployed in critical defense and government applications. The company specializes in autopilots and navigation systems for unmanned aerial vehicles.

Intercepted credentials or compromised firmware images could pose significant security risks to UAV operations in the field. The company advised users to avoid flashing any firmware downloaded on July 24-25 until integrity checks are complete.

Response and Recovery

CubePilot regained control of its domains later on July 24, restored its nameservers, and revoked the fraudulent TLS certificates. Affected systems were taken offline during the incident response.

The company has reported the incident to the Australian Cyber Security Centre and referred the matter for law enforcement investigation.

CubePilot urged users to change passwords if they reused credentials across services. The attack demonstrates how DNS hijacking can bypass traditional security indicators — valid TLS certificates made the malicious infrastructure indistinguishable from legitimate CubePilot services during the window of compromise.

The company's forum and portal were confirmed as affected services. Users who accessed these systems on July 24 should assume their credentials may have been captured and take appropriate precautions.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.