• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
critical deadline: update old .net domains before january 7, 2025

Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

You are here: Home / General Cyber Security News / Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption
January 3, 2025

Microsoft has announced that it’s making an “unexpected change” to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure.

“We expect that most users will not be directly affected, however, it is critical that you validate if you are affected and to watch for downtime or other kinds of breakage,” Richard Lander, a program manager on the .NET team, said in a statement last week.

The move is the result of the fact that some .NET binaries and installers are hosted on Azure Content Delivery Network (CDN) domains that end in .azureedge[.]net — dotnetcli.azureedge.net and dotnetbuilds.azureedge.net — which are hosted on Edgio.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Last month, web infrastructure and security company Akamai acquired select assets from Edgio following its bankruptcy. As part of this transition, the Edgio platform is scheduled to end service on January 15, 2025.

Cybersecurity

Given that the .azureedge[.]net domains could cease to become unavailable in the future, Microsoft said it’s migrating to Azure Front Door CDNs. The Windows maker said it will automatically migrate customers’ workloads by January 7, 2025, if no action is taken.

However, it’s worth noting that automatic migration will not be possible for endpoints with *.vo.msecnd.net domains. Users who plan to migrate to Akamai or another CDN provider are also required to set the Feature Flag DoNotForceMigrateEdgioCDNProfiles before January 7, 2025, so as to prevent automatic migration to Azure Front Door.

“Note you will have until January 14, 2025 to complete your migration to another CDN, but again Microsoft cannot guarantee your services will be available on the Edgio platform before this date,” Microsoft said.

“Please be advised we will need to halt all configuration changes to Azure CDN by Edgio profiles starting on January 3, 2025. This means you will not be able to update your CDN profile configuration, but your services on Azure CDN from Edgio will still operate until you are migrated or the Edgio platform is shut down on January 15, 2025. If you apply the DoNotForceMigrateEdgioCDNProfiles feature flag before January 3, your configuration will not be frozen for changes.”

While relying on *.azureedge[.]net and *.azurefd[.]net isn’t recommended due to availability risks, users have the temporary option of migrating to Azure Front Door while retaining the domains.

“To ensure greater flexibility and avoid a single point of failure, it’s advisable to adopt a custom domain as soon as possible,” Microsoft warns.

Furthermore, to avoid security concerns with a bad actor acquiring the azureedge[.]net domain for malware distribution or poisoning the software supply chain, the tech giant said it has taken control of it. But as for why the old domain names could not be used to resolve to the new servers, it’s being said that “this option wasn’t being made available.”

Cybersecurity

Users are recommended to scan their codebases for references to azureedge[.]net and update them to the following –

  • Update dotnetcli.azureedge.net to builds.dotnet.microsoft.com
  • Update dotnetcli.blob.core.windows.net to builds.dotnet.microsoft.com

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «apple to pay siri users $20 per device in settlement Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations
Next Post: LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers ldapnightmare poc exploit crashes lsass and reboots windows domain controllers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.