vulnerability Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird downloads for Linux after an unencrypted copy was accidentally committed to a private repository. This affects older downloads and requires manual intervention for some users, particularly those checking signatures manually or installing from… The Hacker News · Aug 11, 2026 High gpgkey revocationgithub breach
supply-chain Mozilla Issues New Firefox GPG Key Following Exposure Mozilla has revoked a compromised GPG signing key used for Firefox and Thunderbird, following its accidental exposure in a GitHub repository. While the immediate risk was mitigated due to limited access, the incident hig… SecurityWeek · Aug 11, 2026 Medium gpgsupply-chainkey-rotation