Find notable cyber news and cases, enriched with sources, timelines, and signals.

CubePilot hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

The CubePilot DNS hijacking incident exposed cubepilot[.]org traffic to attacker-controlled infrastructure, creating a risk that credentials entered on affected services could be captured. The attacker also obtained TLS certificates for all cubepilot.org subdomains, so malicious pages could appear trustworthy over HTTPS. CubePilot said it regained control on July 24 and took several services offline while checking the integrity of published firmware. Users were warned to avoid reusing passwords and to treat recent firmware downloads as unsafe until validation is complete.

Related Happenings

CubePilot OEM services and portals offline

Service Disruption
H score1 First: 29.07.2026 00:17 Last: 29.07.2026 00:17 Sources 1

How related: Currently, all OEM services, the community forum, and the documentation portal are offline.

About this happening: CubePilot has taken OEM services, the community forum, the documentation portal, and the ERP portal offline while it investigates a security incident, cutting off...

Timeline

  1. 29.07.2026 00:17 1 articles · 2h ago

    Attacker hijacks cubepilot[.]org DNS and intercepts CubePilot traffic

    Exploitation Observed

    An attacker gained control of cubepilot[.]org DNS settings on July 24 and obtained TLS certificates covering every cubepilot.org subdomain, allowing attacker-controlled infrastructure to intercept traffic intended for CubePilot internal systems and potentially capture credentials entered on the portal, forum, and other services.

    Show sources
  2. 29.07.2026 00:17 2 articles · 2h ago

    CubePilot discloses DNS hijacking and takes services offline

    Initial Disclosure

    CubePilot said it regained control of its domains on July 24, revoked the fraudulently issued certificates, preserved evidence, notified relevant providers, and reported the incident to the Australian Cyber Security Centre and law enforcement; as of July 28, OEM services, the community forum, the documentation portal, and the ERP portal were offline, and firmware images downloaded on July 24-25 were being reviewed for safety.

    Show sources