Feed›Threat Intelligence›Mozilla rotates Firefox and Thunderbird signing key after Gi...
Threat IntelligenceCyber Insider
3.0 — LOW

Mozilla rotates Firefox and Thunderbird signing key after GitHub exposure

📅 11 August 2026 at 14:25 UTC📰 Cyber InsiderView original source ↗
Mozilla rotates Firefox and Thunderbird signing key after GitHub exposure

Mozilla has replaced a GPG subkey used to sign some Firefox and Thunderbird releases after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The organization says its audit records show no evidence that an unauthorized person accessed the key. Mozilla engineer Ben Hearsum disclosed the incident on August … The post Mozilla rotates Firefox and Thunderbird signing key after GitHub exposure appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Mozilla inadvertently exposed a GPG signing key, which was later revoked and replaced with a new one after an unencrypted copy of the previous key was accidentally committed to a private GitHub repository. The incident highlights the importance of secure access controls and auditing in software development.

⚙️Technical Details
💥Impact Assessment
Severity: medium
🛡️Recommended Actions
1Update local keyring to import the new public key
2Remove existing signing key before importing replacement on affected systems
3Verify signing subkey fingerprint when installing RPM packages
📦Affected Products
Firefox: TrueThunderbird: True

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider ↗
← Back to feed