CubePilot, an Australian drone flight controller developer, experienced a severe operational disruption after attackers hijacked its DNS settings to intercept traffic. The attack compromised the company's ability to serve its customer base.
CubePilot designs and manufactures flight controllers for unmanned aerial vehicles (UAVs). The DNS hijacking attack redirected the company's domain traffic to attacker-controlled servers, enabling interception of communications and potential data theft.
DNS hijacking occurs when attackers gain unauthorized access to domain name system records, typically through compromised credentials or exploited vulnerabilities. This allows them to redirect users attempting to reach legitimate services to malicious alternatives.
The attack disrupted CubePilot's operations and affected customers relying on the company's software and services. DNS hijacking poses particular risks to technology vendors, as it can compromise software updates, customer communications, and sensitive data transmission.
CubePilot has not disclosed the full scope of the breach or the number of affected users. The company is working to restore normal operations and secure its systems. The incident underscores growing targeting of supply chain providers in the aerospace and defense sectors.
The Head Mare hacktivist group has compromised TrueConf video conferencing servers and replaced legitimate client installers with trojaned versions containing backdoors.
OpenAI inadvertently launched a denial-of-service attack against Hugging Face, the popular machine learning platform. The incident has prompted questions about AI infrastructure security and unintended consequences of large-scale operations.
Framework's customer database was compromised in a data breach, though payment information was not exposed. The company has disclosed the incident to affected users.
Security researchers have identified potential hardware backdoors in certain x86 processors. The findings, detailed in a GitHub repository called Rosenbridge, reveal vulnerabilities at the processor level that could allow unauthorized access.