-
Notifications
You must be signed in to change notification settings - Fork 148
Description
After releasing MSSQL sink 8.2.1 I received the following alert from nuget.org via email.
Hello,
We are reaching out to inform you of a critical update requirement for the Microsoft.Identity.Client package referenced in your project.
A previous version of this package contained a typo in a comment URL that inadvertently pointed to a typosquatting phishing site:
🔗 hXXps[:]//login[.]microsfoftonline[.]com/common
This URL has been flagged as ConfirmedMaliciousURL by multiple security vendors, including Avira, Sophos, and Bitdefender.
To address this, the team released a fix in version 4.72.1, published on May 20, as documented in their https://github.com/AzureAD/microsoft-authentication-library-for-dotnet/releases/tag/4.72.1.
🚨 Required Action:
Please update to version 4.72.1 or later of Microsoft.Identity.Client immediately on your below packages:Serilog.Sinks.MSSqlServer 8.2.2-dev-00134, 8.2.1, 8.2.1-dev-00132
We appreciate your prompt attention to this matter to help maintain a secure and trustworthy ecosystem.
If you have any questions or need assistance, feel free to reach out.
Best Regards,
NuGet Admin
(tracking: 80c2ec86)