CubePilot, an Australian firm that designs flight controllers for drones (UAVs), has introduced vital operational disruption attributable to a DNS hijacking assault.
Hijacking Area Identify System (DNS) information permits attackers to redirect customers to their very own infrastructure and divert visitors supposed for respectable providers. This exposes customers to harmful situations resembling delicate knowledge interception, malware distribution, and phishing.
In line with an replace revealed on CubePilot’s web site, on July twenty fourth, attackers had been in a position to management the DNS settings of the cubepilot(.)org area and intercept visitors destined for inner techniques.
The attackers additionally obtained TLS certificates protecting all subdomains of cubepilot.org. Which means customers accessing the affected service could have unknowingly accessed attacker-controlled infrastructure and seen a legitimate HTTPS connection.
“The certificates obtained by the attackers coated all subdomains of cubepilot.org, which can have captured credentials entered into any of our providers (together with portals and boards) on July 24,” the announcement reads.
“When you’ve got used the identical password elsewhere, please change it instantly,” CubePilot warned.
CubePilot mentioned it regained management of the area on July 24, revoked the fraudulently issued certificates, preserved proof, notified the related suppliers and reported the incident to the Australian Cyber Safety Heart and legislation enforcement companies.
The corporate additionally promised to instantly notify affected organizations if any impacts are recognized via the investigation.
CubePilot designs “autopilots” and navigation {hardware} for UAVs utilized in surveying, search and rescue, agriculture, in addition to protection and authorities purposes.
The corporate has beforehand publicly introduced help for Ukraine, with its merchandise being delivered to the nation as a part of an Australian authorities help package deal.
All OEM providers, neighborhood boards, and documentation portals are at present offline.
CubePilot CEO Philip Rowse mentioned on LinkedIn that the platform’s ERP portal has additionally been taken offline as a precaution because the investigation into the incident is ongoing.
Relating to the integrity of revealed firmware pictures, CubePilot is at present evaluating them and advises in opposition to flashing pictures downloaded between July 24-25 till checks have been accomplished to make sure their security.
Firmware obtained earlier than July twenty fourth is at present thought of secure to make use of.
Lastly, we suggest that purchasers who obtain a cost request claiming to be from CubePilot take no motion and as a substitute name their traditional contact to verify.

Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remainder strikes invisibly via the setting.
Picus’ whitepaper reveals learn how to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
