← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 11, 2026 · 11:09via CyberPress

Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit

Brief

Mozilla has rotated and revoked a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous key was inadvertently committed to a private GitHub repository.

In an August 10 advisory, Ben Hearsum said Mozilla’s review of available audit records found no evidence that an unauthorized party accessed the key while it was stored in the repository.

Access was restricted to a small group of Mozilla personnel who already had authorized access to the signing key through other channels. Despite no evidence of misuse, Mozilla revoked the previous key as a precaution and introduced safeguards to prevent a repeat incident.

Mozilla Revokes Firefox and Thunderbird GPG Signing Key

The company has moved to a new signing subkey for Linux tarballs, RPM packages, and checksum files associated with Firefox and Thunderbird releases.

Read more on CyberPress