CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack.
Hijacking domain name system (DNS) records allows threat actors to redirect users to their infrastructure, diverting traffic intended for a legitimate service. This exposes users to dangerous scenarios such as sensitive data interception, malware delivery, and phishing.
According to a status update published on CubePilot’s website, an attacker gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems.
The attacker also obtained TLS certificates covering all cubepilot.org subdomains, meaning users visiting affected services would have seen valid HTTPS connections while unknowingly landing on attacker-controlled infrastructure.
“The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured — the portal and the forum included,” reads the announcement.
“If you used the same password anywhere else, change it there now,” warned CubePilot.
CubePilot said it regained control of its domains on July 24, revoked the fraudulently issued certificates, preserved evidence, notified relevant providers, and reported the incident to the Australian Cyber Security Centre and law enforcement.
Also, the company promised to notify affected entities directly where impact is confirmed through its investigation.
CubePilot designs “autopilots” and navigation hardware for UAVs used in surveying, search and rescue, agriculture, and also defense and government applications.
Previously, the company publicly announced its support for Ukraine, and its products have been delivered in the country, including as part of an Australian government assistance package.
... continue reading