CubePilot, an Australian drone flight controller manufacturer, disclosed that attackers hijacked DNS settings for its cubepilot.org domain, redirected users to attacker-controlled infrastructure, and obtained valid TLS certificates for all subdomains. The compromise created a credible risk that credentials and other sensitive traffic entered into services such as the company portal and forum could have been intercepted while still appearing to use legitimate HTTPS connections.
CubePilot said it regained control of the domain the same day, revoked the fraudulent certificates, preserved evidence, and reported the incident to the Australian Cyber Security Centre and law enforcement. As a precaution, the company took OEM services, its community forum, documentation portal, and ERP-related services offline, warned customers not to flash firmware downloaded between July 24 and July 25 until integrity checks are completed, and advised customers to verify any payment requests claiming to be from the company by phone.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
As a precaution after the DNS hijacking, CubePilot took multiple services offline, including OEM services, the community forum, and documentation resources. The company also warned customers not to flash firmware downloaded on July 24–25 until integrity checks are completed and to verify payment requests claiming to be from CubePilot by phone.
CubePilot said it regained control of the cubepilot.org domain on the same day as the attack and revoked the fraudulent TLS certificates. The company also preserved evidence and reported the incident to the Australian Cyber Security Centre and law enforcement.
On July 24, attackers gained unauthorized control of CubePilot's cubepilot.org DNS settings, redirected traffic to attacker-controlled infrastructure, and obtained TLS certificates for all subdomains. The incident created a risk of intercepted traffic and credential capture while still presenting valid HTTPS connections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.