CubePilot 在攻击者劫持 DNS 和 TLS 后将无人机服务下线
首席执行官 Philip Rowse 警告用户更改重复使用的密码,并在 CubePilot 验证已发布的镜像期间避免使用于7月24日至25日下载的固件。
By Ryan Merket · Published
Primary source: CubePilot
Why it matters
CubePilot's breach reached the trust layer around drone hardware: valid certificates, customer credentials and firmware distribution. Its checksum review will determine whether the incident remained an account compromise or touched aircraft software.

CubePilot, led by CEO Philip Rowse, took its firmware, documentation, community forum and OEM services offline after an attacker seized control of its domain-name settings and obtained valid security certificates for every cubepilot.org subdomain.
攻击者夺取了 CubePilot 的域名设置并为每个 cubepilot.org 子域名获取了有效的安全证书后,CubePilot(首席执行官为 Philip Rowse)将其固件、文档、社区论坛和 OEM 服务下线。
The attacker controlled CubePilot's DNS for part of July 24th and used it to intercept traffic intended for internal business systems, according to CubePilot's security notice. Credentials entered into the portal, forum or other affected services that day may have been captured. BleepingComputer reported that the certificates would have allowed attacker-controlled services to display valid HTTPS connections.
根据 CubePilot 的安全通知,攻击者在 7 月 24 日的一段时间内控制了 CubePilot 的 DNS,并利用该控制截获了原本发往内部业务系统的流量。那天在门户、论坛或其他受影响服务中输入的凭据可能已被捕获。BleepingComputer 报道 称,这些证书会使攻击者控制的服务显示为有效的 HTTPS 连接。
CubePilot regained control of the domains and restored its nameservers on July 24th, then revoked the fraudulently issued certificates. As of July 29th, CubePilot's notice still marked the incident as open. Reseller and OEM ordering, quotes and support remained offline, along with the documentation portal and community forum. Firmware checks were still in progress. Email on cubepilot.com was operating.
CubePilot 于 7 月 24 日重新获得了域名控制并恢复了其域名服务器,然后撤销了被欺诈性签发的证书。截至 7 月 29 日,CubePilot 的通知仍将该事件标记为未结。经销商和 OEM 的订购、报价与支持仍处于离线状态,文档门户和社区论坛亦如此。固件核查仍在进行中。cubepilot.com 的电子邮件在运行。
The incident reaches into a sensitive part of the drone component stack. CubePilot supplies flight controllers, navigation hardware and related systems used to configure and operate uncrewed aircraft. Those products serve commercial applications including surveying and agriculture, alongside government and defense deployments. A breach of the channels used to distribute firmware and technical instructions creates a different class of risk from a conventional corporate-site compromise.
该事件波及了无人机组件堆栈中一个敏感的部分。CubePilot 提供飞行控制器、导航硬件及用于配置和操作无人飞行器的相关系统。这些产品用于测绘、农业等商业应用,也用于政府和国防部署。用于分发固件和技术说明的通道被入侵,与传统的公司网站被攻破相比,会产生不同类别的风险。
A trusted connection to the wrong server
通向错误服务器的受信任连接
DNS converts a domain such as cubepilot.org into the network address a user's computer contacts. Control of those records allowed the attacker to direct CubePilot traffic to infrastructure outside CubePilot's control. The valid TLS certificates removed a warning that might otherwise have alerted users: browsers could show a normal encrypted connection while sending information to the attacker's server.
DNS 将像 cubepilot.org 这样的域名转换为用户计算机需要联系的网络地址。对这些记录的控制使攻击者能够将 CubePilot 的流量定向到 CubePilot 无法控制的基础设施。有效的 TLS 证书移除了可能会提醒用户的警告:浏览器会显示正常的加密连接,同时实际上将信息发送到攻击者的服务器。
CubePilot has told anyone who entered credentials on July 24th to change reused passwords. It also warned customers to treat requests for passwords, verification codes or payment details as hostile, and to confirm changed bank details or payment requests by calling their usual CubePilot contact.
CubePilot 已通知在 7 月 24 日输入凭据的任何人更改重复使用的密码。它还警告客户将对密码、验证码或付款详情的请求视为敌对行为,并通过致电其常用的 CubePilot 联系人来确认更改后的银行信息或付款请求。
Those instructions point to two immediate risks. The first is credential reuse, which can turn one captured password into access to unrelated corporate systems. The second is invoice fraud against resellers and drone manufacturers already accustomed to receiving quotes, support messages and payment instructions through CubePilot's business infrastructure.
这些指示指出了两个直接风险。第一个是凭证重复使用——被捕获的一个密码可能被用来访问无关的企业系统。第二个是针对经销商和无人机制造商的发票欺诈,因为这些方习惯通过 CubePilot 的业务基础设施接收报价、支持信息和付款指示。
CubePilot said it preserved evidence, notified relevant service providers, reported the incident to the Australian Cyber Security Centre and referred it to law enforcement. CubePilot is working through which data was reachable during the unauthorized-access period.
CubePilot 表示已保留证据、通知相关服务提供商、向澳大利亚网络安全中心报告该事件并将其移交执法部门。CubePilot 正在核查在未经授权访问期间哪些数据是可访问的。
Firmware verification sets the stakes
固件验证决定事态严重性
The most consequential review concerns firmware images downloaded on July 24th and July 25th. CubePilot instructed users to avoid flashing those files while it verifies checksums for every published image. CubePilot considers images obtained before July 24th unaffected.
最重要的审查涉及在 7 月 24 日和 7 月 25 日下载的固件镜像。CubePilot 指示用户在其对每个已发布镜像验证校验和期间不要刷写这些文件。CubePilot 认为在 7 月 24 日之前获取的镜像不受影响。
The warning does not establish that firmware was altered. It shows that CubePilot cannot yet rely on the affected distribution path as proof that users received the files CubePilot intended to publish. Checksum verification should determine whether the downloadable images match known builds.
该警告并未证明固件被篡改。它表明 CubePilot 目前仍无法依赖受影响的分发路径,作为用户是否收到 CubePilot 本意发布文件的证明。校验和验证应能确定可下载的镜像是否与已知构建一致。
That distinction matters for autopilot hardware. Firmware can govern sensors, navigation, communications and flight behavior. A corrupted business portal can expose accounts and invoices; a compromised firmware image could cross from information systems into an aircraft. CubePilot's current evidence establishes intercepted traffic and possible credential theft. The firmware review is the control that separates that confirmed incident from a possible software supply-chain compromise.
这一区别对于自动驾驶(autopilot)硬件至关重要。固件可以控制传感器、导航、通信和飞行行为。被破坏的业务门户可能暴露账户和发票;被篡改的固件镜像则可能从信息系统蔓延到飞行器本身。CubePilot 目前的证据证实了流量被截获并可能存在凭证被窃的情况。固件审查是将已确认的事件与可能的软件供应链妥协区分开的控制措施。
Rowse built his career around the hardware now under review. ArduPilot's commercial-support directory credits him with years of autopilot design work, including the Pixhawk 2.1, sold as the CubePilot CubeBlack and used in the 3DR Solo. The Pixhawk project lists CubePilot as the current manufacturer of the Pixhawk 2 design.
Rowse 的职业生涯围绕着目前正在审查的硬件展开。ArduPilot 的商业支持目录 将多年的自动驾驶设计工作归功于他,其中包括 Pixhawk 2.1,该型号以 CubePilot CubeBlack 的名称出售,并用于 3DR Solo。Pixhawk 项目 将 CubePilot 列为 Pixhawk 2 设计的现任制造商。
CubePilot also has deep ties to the open-source software used by drone builders. Rowse said in a 2024 CubePilot forum post that fellow director Michael Oborne is part of CubePilot Global. Oborne created Mission Planner, the open-source ground-control application used to configure and operate ArduPilot aircraft. The Mission Planner repository contains thousands of commits and documents dependencies on multiple firmware, update and support services.
CubePilot 与无人机构建者使用的开源软件也有着深厚的联系。Rowse 在一篇 2024 年的 CubePilot 论坛帖子 中表示,董事会成员 Michael Oborne 属于 CubePilot Global。Oborne 创建了 Mission Planner,这是用于配置和操作 ArduPilot 飞机的开源地面控制应用。Mission Planner 的代码仓库 包含数千次提交,并记录了对多种固件、更新和支持服务的依赖关系。
That history gives CubePilot credibility among engineers who assemble aircraft from interoperable hardware and open-source software. It also concentrates trust in documentation, downloads, forums and support systems that sit outside the aircraft itself. Builders need those services to configure boards, resolve faults and decide which software to install.
这一历史使 CubePilot 在使用可互操作硬件和开源软件组装飞行器的工程师中具有信誉。它也将信任集中在飞行器本身之外的文档、下载、论坛和支持系统上。构建者需要这些服务来配置板子、排查故障并决定安装哪款软件。
Drone supply-chain scrutiny moves up the stack
无人机供应链审查上移至更高层
CubePilot has spent years positioning its manufacturing and ownership for government and defense buyers. Rowse wrote in 2024 that CubePilot Global had moved operations to Australia and Taiwan, with most products made in Taiwan or the US. CubePilot Global is an active Australian private company registered from July 2023, according to the Australian Business Register.
多年来,CubePilot 一直在为政府和国防买家调整其制造和所有权结构。Rowse 在 2024 年写道,CubePilot Global 已将业务迁至澳大利亚和台湾,大多数产品在台湾或美国制造。根据 Australian Business Register,CubePilot Global 自 2023 年 7 月起为一家在册的澳大利亚私人公司。
Hardware provenance is only one part of that procurement case. The July 24th incident shows that control over domains, certificate issuance, firmware hosting and customer portals can become equally important. A trusted circuit board can still receive software or instructions through a compromised distribution channel.
硬件来源只是采购考量的一部分。7 月 24 日的事件表明,对域名、证书签发、固件托管和客户门户的控制同样重要。即便是受信任的电路板,也可能通过被攻破的分发通道接收到软件或指令。
CubePilot's response reduced the immediate exposure by restoring the nameservers, revoking certificates and shutting services down. The operational cost is visible: customers cannot use normal ordering, documentation or support channels while verification continues. For a specialist supplier serving drone manufacturers, resellers and government-linked programs, those channels are part of the product. Their security determines whether customers can trust the hardware after it leaves the factory.
CubePilot 的应对措施通过恢复域名服务器、撤销证书并关闭服务来降低了即时风险。其运营代价显而易见:在验证进行期间,客户无法使用正常的订购、文档或支持渠道。对于为无人机制造商、经销商和与政府相关项目提供服务的专业供应商而言,这些渠道本身就是产品的一部分。它们的安全性决定了客户在硬件离开工厂后是否仍能信任该硬件。