Mozilla Revokes Firefox Signing Key After Unencrypted Exposure on GitHub

Mozilla Revokes Firefox Signing Key After Unencrypted Exposure on GitHub

First seen 11 Aug 2026, 12:08 UTC GbhackersTheregister 88% similarity 39.9

Article Content

Browse articles
ThreatCluster

Mozilla has revoked a GPG signing subkey for Firefox and Thunderbird after an unencrypted copy was accidentally committed to a private GitHub repository. The subkey, used for signing Linux tarballs, RPM packages, and checksum files, was accessible only to a limited number of authorized Mozilla employees. An investigation revealed no unauthorized access to the key while it was exposed. Mozilla has implemented additional safeguards but did not disclose how long the key was in the repository or how it was committed. Users of Firefox and Thunderbird are not required to take action, but those manually verifying signatures will need to import the new signing key. RPM users on certain distributions will need to manually update their keys. The incident highlights the risks associated with handling cryptographic keys in source control environments.

Key Points: • Mozilla revoked a GPG signing subkey after it was accidentally exposed on GitHub. • The exposed key was used for signing release files for Firefox and Thunderbird. • No unauthorized access was detected during the key's exposure period.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
Mozilla revokes GPG signing subkey
An unencrypted copy of the subkey was committed to a private GitHub repository, leading to its revocation.
Theregister
2026-08-11
Mozilla announces additional safeguards
Following the incident, Mozilla has implemented new measures to prevent similar occurrences in the future.
Gbhackers

Community

Browse all →

Tracked Entities in This Story