supply-chain
Mozilla Issues New Firefox GPG Key Following Exposure
Medium
Summary
Mozilla has revoked a compromised GPG signing key used for Firefox and Thunderbird, following its accidental exposure in a GitHub repository. While the immediate risk was mitigated due to limited access, the incident highlights the ongoing threat of supply chain attacks and the importance of key rotation practices. Users who manually verify GPG signatures will need to update their key trust stores.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data