By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CubePilot Suffers DNS Hijacking Attack
CubePilot, an Australian company specializing in the development of flight controllers for unmanned aerial vehicles (UAVs), announced on May 21, 2024, that it had been subjected to a significant DNS hijacking attack. This cyberattack led to a severe disruption of the company's operational capabilities. The nature of the attack involved the compromise of CubePilot's Domain Name System (DNS) infrastructure, a critical component that translates human-readable domain names into machine-readable IP addresses. By hijacking the DNS, attackers could redirect CubePilot's legitimate traffic to malicious servers, potentially intercepting sensitive data and disrupting services.
The company stated that the incident impacted its ability to provide essential services to its customers, which include users of its Pixhawk flight controller hardware and associated software. The Pixhawk is a widely adopted open-source autopilot hardware designed for a variety of UAV applications, from hobbyist drones to professional surveying and agricultural aircraft. CubePilot's announcement indicated that the attack had been ongoing for an unspecified period before detection, raising concerns about the extent of potential data exposure. The company has initiated an investigation into the incident and is working to restore normal operations.
While CubePilot has not yet disclosed the specific methods used in the DNS hijacking, such attacks typically involve gaining unauthorized access to a domain registrar account or exploiting vulnerabilities in DNS hosting services. Once control of the DNS records is achieved, attackers can manipulate where internet traffic is directed. This could involve redirecting users to fake login pages to steal credentials, serving malware, or intercepting communications between CubePilot's servers and its users. The company has advised its customers to remain vigilant and monitor their systems for any unusual activity.
CubePilot is a key player in the drone industry, providing the foundational technology for many autonomous flight systems. The disruption caused by this attack highlights the cybersecurity risks inherent in the growing drone ecosystem, where sophisticated control systems rely on secure network infrastructure. The company's commitment to investigating the breach and implementing corrective measures is crucial for regaining the trust of its user base and ensuring the continued integrity of its products and services. Further details regarding the scope of the attack and any confirmed data breaches are expected to be released as the investigation progresses.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.