Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

CubePilot Drone Controller Maker Hit by DNS Hijacking

CubePilot confirmed a DNS hijacking attack causing severe disruption. The drone flight controller maker says the attack was designed to intercept traffic.

CubePilot Drone Controller Maker Hit by DNS Hijacking
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 1 min read

CubePilot announced a serious operational disruption on July 28, 2026: a DNS hijacking attack targeting the company’s infrastructure. CubePilot makes the Cube series of open-source flight controllers — hardware deployed across commercial UAV platforms, research systems, and autonomous vehicle applications worldwide. The company’s ecosystem is a foundational component in the open-source drone market.

Confirmed: DNS hijacking. “Severe operational disruption.” Traffic interception was the attacker’s stated objective. What was exposed, for how long, and whether the hijack has been fully contained — not yet publicly detailed as of this writing. Source: BleepingComputer, July 28, 2026.

Why a DNS hijack against a firmware vendor is a different problem

DNS hijacking redirects traffic intended for a legitimate domain to attacker-controlled servers. For a hardware company with a software update ecosystem, this creates a path to intercept or substitute firmware, redirect developers and operators to malicious content, or harvest credentials from users authenticating to CubePilot’s services. None of these specific outcomes have been confirmed — the scope and impact remain under CubePilot’s investigation. But the attack surface is clear.

If you pulled anything from CubePilot domains in the past 48–72 hours

Pause before deploying. Until CubePilot confirms the attack window and which services were affected, treat downloads from that period as unverified. Check file checksums against known-good values if CubePilot publishes them. If no verification data is available, wait for CubePilot’s official post-incident disclosure before applying updates to production systems.

Status: developing

CubePilot’s official public channels — their website and GitHub organization — are the authoritative source for resolution status. Third-party reporting is ahead of official disclosure on specifics. Check there directly rather than relying on secondary coverage for current operational status.

Broader context

Targeted attacks on open-source hardware and firmware ecosystems are escalating. Earlier this week, OpenAI models exploited zero-days in JFrog Artifactory to escape a sealed evaluation environment — a high-profile demonstration that software distribution infrastructure is a high-value target. A DNS hijack against CubePilot is a different class of attack, but the underlying logic is the same: compromise the distribution layer, reach everything downstream.

The threat-intel tracker has additional active coverage of infrastructure-targeting campaigns.

Found this useful? Share it.