Mozilla says it replaced a GPG signing subkey used for some Firefox and Thunderbird release files after the private key was accidentally committed to a GitHub repository. The exposed key signed Linux tarballs, RPM packages, and checksum files; Mozilla said the repository was private, only a small group of developers could access it, and its audit review found no evidence of unauthorized access, but it revoked the key and issued a new one as a supply-chain precaution.
Why it matters: Release-signing keys help users and systems verify that software downloads are genuine, so even a limited exposure is serious. Organizations and users that manually verify Firefox or Thunderbird signatures, especially RPM package users, should import Mozilla’s new key and follow the vendor’s update instructions.
Sergiu Gatlan
2026.08.11
99% relevant
This is the same incident and adds Mozilla's confirmation that the exposed unencrypted subkey was used for Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files, that no unauthorized access was found in audit logs, and that some Linux users must manually import the new key or update RPM trust settings.
info@thehackernews.com (The Hacker News)
2026.08.11
96% relevant
This article reports the same underlying event: Mozilla revoked the Linux signing key for Firefox and Thunderbird after the private key was exposed in a repository, adding source confirmation and coverage details around the revocation and affected Linux packages.
2026.08.11
98% relevant
This article directly updates the same event by adding operational detail on who must manually replace the revoked key, which package formats were signed with it, and Mozilla's statement that audit logs found no unauthorized access.
Eduard Kovacs
2026.08.11
100% relevant
This article establishes a distinct supply-chain security event centered on Mozilla's own signing-key exposure and rotation, not a patch, CVE, or previously tracked compromise.
← Back to all stories