threat-intel Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub Mozilla has revoked a signing key for Firefox after an unencrypted copy of the key was accidentally uploaded to GitHub. This significantly increases the risk of malicious actors creating fake Firefox installations. The incident highlights a critical vulnerability in Firefox's signing process and underscores the importa… The Register · Aug 11, 2026 High key-managementfirefoxvulnerability