threat-intel
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
High
Summary
Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The incident highlights a critical vulnerability in Firefox's signing process and underscores the importance of secure key management.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data