
CubePilot, the Australian company that makes autopilot and navigation hardware for commercial and government drones, disclosed that an attacker gained control of its cubepilot.org DNS settings on July 24, 2026. By redirecting the domain’s DNS records to infrastructure they controlled, the attacker was able to intercept traffic meant for CubePilot’s internal services — and, critically, to obtain TLS certificates covering every cubepilot.org subdomain. That means anyone visiting CubePilot’s services on that date would have seen a valid HTTPS padlock while their connection went to an attacker-controlled server.
CubePilot’s community forum and OEM customer portal were both within scope of the hijacked domain. The company confirmed that “credentials entered on any of our services on 24 July may have been captured — the portal and the forum included.” The firm regained control of its domain the same day, revoked the fraudulently issued certificates, and reported the incident to the Australian Cyber Security Centre and law enforcement. An investigation is ongoing. As a precaution, CubePilot took all OEM services, the forum, and the documentation portal offline; the ERP portal was also suspended. The company also warned customers not to flash firmware images downloaded on July 24–25 until integrity checks are complete, and to verify any payment requests from CubePilot by phone rather than acting on them directly. Firmware obtained before July 24 is considered safe.
CubePilot’s hardware — branded under the Cube and Pixhawk lines — is used in surveying, search and rescue, agriculture, and defence applications. Its products have been supplied to Ukraine as part of an Australian government assistance package, which gives the incident some geopolitical weight. The company has promised to notify confirmed affected customers directly as its investigation progresses.
How to check if you’re affected
Affected products include any firmware or software downloaded from cubepilot.org between July 24 and July 25, 2026. If you accessed the CubePilot portal or community forum on July 24 and entered your password, treat that password as compromised. Change it immediately, and change it on any other site where you used the same password. Do not flash firmware downloaded during the July 24–25 window until CubePilot issues a clean-bill advisory.
Sources
- CubePilot drone software dev hit by DNS hijacking to intercept traffic — BleepingComputer
- CubePilot incident status update (cubepilot.org — currently offline for investigation)
