Mozilla revoked and replaced a GPG signing subkey used for certain Firefox and Thunderbird release artifacts after an unencrypted copy of the previous private subkey was accidentally committed to a private GitHub repository. The exposed key had been used to sign Linux tarballs, RPM packages, and checksum files. Mozilla said its review found no evidence of unauthorized access while the key was in the repository, noting that access was limited to a small internal group that already had authorized access by other means.
The company published a new signing key, issued a revocation for the old one, and said it has added safeguards to prevent a similar incident. Mozilla said most users do not need to take action, but users who manually verify GPG signatures must import the new key and the revocation certificate. Some Firefox RPM users may also need manual remediation because certain package managers do not automatically replace revoked keys, and Mozilla provided distro-specific guidance for Fedora, RHEL, Rocky, AlmaLinux, and openSUSE/SUSE systems.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Mozilla rotated to a new GPG signing subkey for affected Firefox and Thunderbird artifacts, including Linux tarballs, RPM packages, and checksum files, and revoked the previous signing key. Mozilla also said it added safeguards to prevent similar key-handling issues in the future.
After reviewing available audit records, Mozilla said it found no evidence that any unauthorized party accessed the signing key while it was present in the private repository.
Mozilla said an unencrypted copy of the previous GPG signing subkey for certain Firefox and Thunderbird release artifacts was inadvertently committed to a private GitHub repository. The repository was accessible only to a small internal group that already had authorized access to the key by other means.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
10 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourceblog.mozilla.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.