Mozilla Firefox Signing Key: Critical Revocation
ID: 49016fab-1a40-5846-95c2-9774ec3da3f3
STIX ID: report--49016fab-1a40-5846-95c2-9774ec3da3f3
Feed Name: CyberNexora News
Mozilla revoked a GPG signing subkey after an unencrypted copy was accidentally committed to a private GitHub repository; the key signed Firefox and Thunderbird Linux packages, tarballs, and checksum files. Mozilla found no evidence of unauthorized access or misuse, provided replacement keys and a revocation certificate, and advised administrators and users (particularly on older Fedora/RHEL/Rocky/AlmaLinux/SUSE systems) to obtain and verify the new key material and update procedures to protect signing keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
