logo

Mozilla Firefox Signing Key: Critical Revocation

ID: 49016fab-1a40-5846-95c2-9774ec3da3f3

STIX ID: report--49016fab-1a40-5846-95c2-9774ec3da3f3

Feed Name: CyberNexora News

Threat Score
40/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: Debolina Barik

...
...

Mozilla revoked a GPG signing subkey after an unencrypted copy was accidentally committed to a private GitHub repository; the key signed Firefox and Thunderbird Linux packages, tarballs, and checksum files. Mozilla found no evidence of unauthorized access or misuse, provided replacement keys and a revocation certificate, and advised administrators and users (particularly on older Fedora/RHEL/Rocky/AlmaLinux/SUSE systems) to obtain and verify the new key material and update procedures to protect signing keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.