Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.
However, in a Monday blog post, it noted that the risk of a supply chain attack in which threat actors could distribute malicious installers signed with the exposed key is low because only a limited number of individuals had access to the GitHub repository.
Additionally, Mozilla has yet to find evidence that the previous GPG key was accessed by unauthorized parties while being exposed.
After discovering the incident, the organization revoked the key used to sign Linux tarballs, RPM packages, and checksum files, and has taken measures to prevent similar issues in the future.
“Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository,” it noted.
“Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Access to the repository was limited to a small group within Mozilla, all of whom already had authorized access to the key through other means.”
While most users will not have to take any action after the GPG key’s rotation, Mozilla says that users who manually verify GPG signatures must import the new signing key and the revocation for the old key.
It also added that Linux users who install Firefox using RPM packages may need to manually update their systems and shared detailed instructions on what actions are required on systems running Fedora 43 and later, Fedora 42 and older, RHEL/Rocky/Almalinux, and openSUSE/SUSE-based distributions to continue receiving the latest Firefox updates.
Since Thunderbird does not provide official RPM packages, no RPM-specific action is required for Thunderbird users.
The new signing subkey expires August 5, 2028, and the new public key and revocation for the previous key are available through the latest Firefox Nightly KEY files and keys.openpgp.org.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
GitHub, PyPI add time-based defenses against supply chain attacks
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
AsyncAPI npm packages infected with credential-stealing malware
Nearly 300 GitHub repos pose as legit software to push malware
Clean GitHub repo tricks AI coding agents into running malware
Hackers breach TrueConf to trojanize client installers with backdoors
LexisNexis shuts down services after suspicious activity on servers
Valve notifies Steam hardware customers of a data breach
See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Overdue a password health-check? Audit your Active Directory for free
AI is a data-breach time bomb: Read the new report
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



