Thursday , June 5 2025
.NET

Microsoft warn dev urgently to update .NET installer link

Microsoft is forcing .NET developers to quickly update their apps and developer pipelines so they do not use ‘azureedge.net’ domains to install .NET components, as the domain will soon be unavailable due to the bankruptcy and imminent shutdown of CDN provider Edgio.

Specifically, the domains “dotnetcli.azureedge.net” and “dotnetbuilds.azureedge.net” will be taken offline in the next few months, which could break the functionality of projects relying on the domains.

CVSS 9.6: IBM QRadar & Cloud Pak Security Flaws Exposed

IBM has issued a security advisory for vulnerabilities in its QRadar Suite Software and Cloud Pak for Security platforms. These...
Read More
CVSS 9.6: IBM QRadar & Cloud Pak Security Flaws Exposed

ALERT
Thousands of IP addresses compromised nationwide: CIRT warn

As Bangladesh prepares for the extended Eid-ul-Adha holidays, the BGD e-GOV Computer Incident Response Team (CIRT) has issued an urgent...
Read More
ALERT  Thousands of IP addresses compromised nationwide: CIRT warn

New Android Malware ‘Crocodilus’ Targets Banks in 8 Countries

In March 2025, the Threatfabric mobile Threat Intelligence team identified Crocodilus, a new Android banking Trojan designed for device takeover....
Read More
New Android Malware ‘Crocodilus’ Targets Banks in 8 Countries

Qualcomm Patches 3 Zero-Days Used in Targeted Android Attacks

Qualcomm has issued security patches for three zero-day vulnerabilities in the Adreno GPU driver, affecting many chipsets that are being...
Read More
Qualcomm Patches 3 Zero-Days Used in Targeted Android Attacks

Critical RCE Flaw Patched in Roundcube Webmail

Roundcube Webmail has fixed a critical security flaw that could enable remote code execution after authentication. Disclosed by security researcher...
Read More
Critical RCE Flaw Patched in Roundcube Webmail

Hacker claim Leak of Deloitte Source Code & GitHub Credentials

A hacker known as "303" claim to breach the company's systems and leaked sensitive internal data on a dark web...
Read More
Hacker claim Leak of Deloitte Source Code & GitHub Credentials

CISA Issued Guidance for SIEM and SOAR Implementation

CISA and ACSC issued new guidance this week on how to procure, implement, and maintain SIEM and SOAR platforms. SIEM...
Read More
CISA Issued Guidance for SIEM and SOAR Implementation

Linux flaws enable password hash theft via core dumps in Ubuntu, RHEL, Fedora

The Qualys Threat Research Unit (TRU) found two local information-disclosure vulnerabilities in Apport and systemd-coredump. Both issues are race-condition vulnerabilities....
Read More
Linux flaws enable password hash theft via core dumps in Ubuntu, RHEL, Fedora

Australia enacts mandatory ransomware payment reporting

New ransomware payment reporting rules take effect in Australia yesterday (May 30) for all organisations with an annual turnover of...
Read More
Australia enacts mandatory ransomware payment reporting

Why Govt Demands Foreign CCTV Firms to Submit Source Code?

Global makers of surveillance gear have clashed with Indian regulators in recent weeks over contentious new security rules that require...
Read More
Why Govt Demands Foreign CCTV Firms to Submit Source Code?

This includes developers using .NET installers residing on the affected domains, organizations using GitHub Actions or Azure DevOps with custom pipelines using those domains, Docker and script users with files and code referencing the retired domains, and more.

“We maintain multiple Content Delivery Network (CDN) instances for delivering .NET builds. Some end inazureedge.net. These domains are hosted by edg.io, which will soon cease operations due to bankruptcy. We are required to migrate to a new CDN and will be using new domains going forward,” explains Microsoft.

“It is possible that azureedge.net domains will have downtime in the near-term. We expect that these domains will be permanently retired in the first few months of 2025.”

Microsoft recommends that potentially impacted developers search their code, scripts, and configurations for references to azureedge.net and dotnetcli.blob.core.windows.net and replace them with builds.dotnet.microsoft.com.

During the transition, the new domains will be catered by a combination of Edgio, Akamai, and Azure Front Door, as Microsoft works on solidifying the final distribution model with other CDN providers.

CI/CD teams need to ensure GitHub Actions (actions/setup-dotnet) and Azure DevOps tasks are updated to versions supporting the new domains, while updates for Azure DevOps Server are expected in early 2025.

Additionally, given that new CDN domains will now be used, even when configurations are auto-updated, firewalls need to be set to allow traffic from the new locations (builds.dotnet.microsoft.com and ci.dot.net).

The tech giant notes that the timing is quite unfortunate, as impacted users are requested to take action during the holidays when most IT teams are understaffed.

When asked why Microsoft can’t simply transfer the domains and continue using them, Rich Lander, Program Manager of .NET at Microsoft, said it was not possible.

“We asked the same question. We were told that this option wasn’t being made available. We don’t have more information on that,” explained Lander.

The answer is confusing as Microsoft’s Scott Hanselman confirmed that Microsoft already obtained ownership of the domains, stating that “no other party will ever have access to use these domains.”

By owning the domains and preventing their reuse, the chances of a supply chain compromise for those not migrating their applications are minimal. However, it still doesn’t explain the sudden rush to migrate domains and the risks of operational disruptions.

If you’re impacted, you can follow the issue more closely and access status updates on this GitHub page. Microsoft didnt replay BleepingComputer query regarding the issue.

Check Also

mobile

Bank server compromised using customer’s mobile, steal ₹11 crore

Cyber fraudsters hacked the Himachal Pradesh State Cooperative Bank’s server using a customer’s mobile phone. …

Leave a Reply

Your email address will not be published. Required fields are marked *