CubePilot drone software dev hit by DNS hijacking to intercept traffic

www.bleepingcomputer.com/news/secu…

Australian drone flight-controller company CubePilot suffered a DNS hijacking attack on 24 July 2026 that allowed an attacker to control the cubepilot.org domain and intercept traffic intended for internal systems. The attacker also obtained valid TLS certificates covering every subdomain.

Credentials entered on affected services that day may have been captured. CubePilot regained control the same day, revoked the fraudulent certificates, preserved evidence, notified providers, and reported the incident to the Australian Cyber Security Centre and law enforcement. Users who reused passwords elsewhere were urged to change them immediately.

Edward Kiledjian @ekiledjian