• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
critical deadline: update old .net domains before january 7, 2025

Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

You are here: Home / General Cyber Security News / Critical Deadline: Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption
January 3, 2025

Microsoft has announced that it’s making an “unexpected change” to the way .NET installers and archives are distributed, requiring developers to update their production and DevOps infrastructure.

“We expect that most users will not be directly affected, however, it is critical that you validate if you are affected and to watch for downtime or other kinds of breakage,” Richard Lander, a program manager on the .NET team, said in a statement last week.

The move is the result of the fact that some .NET binaries and installers are hosted on Azure Content Delivery Network (CDN) domains that end in .azureedge[.]net — dotnetcli.azureedge.net and dotnetbuilds.azureedge.net — which are hosted on Edgio.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Last month, web infrastructure and security company Akamai acquired select assets from Edgio following its bankruptcy. As part of this transition, the Edgio platform is scheduled to end service on January 15, 2025.

Cybersecurity

Given that the .azureedge[.]net domains could cease to become unavailable in the future, Microsoft said it’s migrating to Azure Front Door CDNs. The Windows maker said it will automatically migrate customers’ workloads by January 7, 2025, if no action is taken.

However, it’s worth noting that automatic migration will not be possible for endpoints with *.vo.msecnd.net domains. Users who plan to migrate to Akamai or another CDN provider are also required to set the Feature Flag DoNotForceMigrateEdgioCDNProfiles before January 7, 2025, so as to prevent automatic migration to Azure Front Door.

“Note you will have until January 14, 2025 to complete your migration to another CDN, but again Microsoft cannot guarantee your services will be available on the Edgio platform before this date,” Microsoft said.

“Please be advised we will need to halt all configuration changes to Azure CDN by Edgio profiles starting on January 3, 2025. This means you will not be able to update your CDN profile configuration, but your services on Azure CDN from Edgio will still operate until you are migrated or the Edgio platform is shut down on January 15, 2025. If you apply the DoNotForceMigrateEdgioCDNProfiles feature flag before January 3, your configuration will not be frozen for changes.”

While relying on *.azureedge[.]net and *.azurefd[.]net isn’t recommended due to availability risks, users have the temporary option of migrating to Azure Front Door while retaining the domains.

“To ensure greater flexibility and avoid a single point of failure, it’s advisable to adopt a custom domain as soon as possible,” Microsoft warns.

Furthermore, to avoid security concerns with a bad actor acquiring the azureedge[.]net domain for malware distribution or poisoning the software supply chain, the tech giant said it has taken control of it. But as for why the old domain names could not be used to resolve to the new servers, it’s being said that “this option wasn’t being made available.”

Cybersecurity

Users are recommended to scan their codebases for references to azureedge[.]net and update them to the following –

  • Update dotnetcli.azureedge.net to builds.dotnet.microsoft.com
  • Update dotnetcli.blob.core.windows.net to builds.dotnet.microsoft.com

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «apple to pay siri users $20 per device in settlement Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations
Next Post: LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers ldapnightmare poc exploit crashes lsass and reboots windows domain controllers»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
  • Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack
  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

Copyright © TheCyberSecurity.News, All Rights Reserved.