CubePilot said a DNS hijacking attack on its cubepilot[.]org domain let an attacker redirect traffic, capture credentials, and obtain valid TLS certificates for all subdomains. The company has restored control, revoked the certificates, taken key services offline, and warned users to reset passwords and avoid firmware downloaded on July 24-25. #CubePilot #cubepilotorg #PhilipRowse
Keypoints
- CubePilot suffered a severe disruption after its DNS settings were hijacked.
- The attacker redirected traffic from cubepilot[.]org to attacker-controlled infrastructure.
- Valid TLS certificates for all cubepilot.org subdomains may have exposed user credentials.
- CubePilot regained control, revoked fraudulent certificates, and reported the incident to authorities.
- The company advised users to change reused passwords and avoid firmware downloaded on July 24-25.