CubePilot announced on July 24 that its DNS settings were hijacked, redirecting traffic to malicious infrastructure. Attackers mimicked secure HTTPS connections covering all subdomains with TLS certificates, collecting users' credentials. The company advised affected users to change their passwords.
The attack also redirected traffic intended for CubePilot's internal systems. The company recommended not using software images downloaded after the attack without verifying their security. Software downloaded before July 24 was considered safe.
CubePilot advised against using software images downloaded after the attack without verifying their security. The company recommended not using software images downloaded after the attack without verifying their security. The company recommended not using software images downloaded after the attack without verifying their security.
