Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Home/CyberSecurity News/Mozilla Revokes Firefox Signing Key After GitHub Exposure of Subkey
CyberSecurity News

Mozilla Revokes Firefox Signing Key After GitHub Exposure of Subkey

Key Takeaways Mozilla has revoked a GPG signing subkey after its unencrypted copy was inadvertently committed to a private GitHub repository. The exposed key was used for signing specific Firefox and...

Emy Elsamnoudy
Emy Elsamnoudy
August 11, 2026 4 Min Read
2 0

Key Takeaways

  • Mozilla has revoked a GPG signing subkey after its unencrypted copy was inadvertently committed to a private GitHub repository.
  • The exposed key was used for signing specific Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files.
  • While Mozilla found no evidence of unauthorized access or misuse, the revocation is a precautionary measure to maintain software supply-chain integrity.
  • Most users will not be affected, but those who manually validate GPG signatures or use certain Linux distributions (e.g., older Fedora, RHEL, Rocky Linux) must take manual steps to update their signing keys.

Mozilla Revokes Firefox Signing Key After Internal GitHub Exposure

Mozilla has taken swift action to rotate a GPG signing subkey following its accidental exposure within a private GitHub repository. The unencrypted subkey, integral to signing specific release artifacts for Firefox and Thunderbird, was inadvertently committed, prompting a precautionary revocation by the organization.

Table Of Content

  • Key Takeaways
  • Mozilla Revokes Firefox Signing Key After Internal GitHub Exposure
  • Details of the Incident
  • Importance of GPG Signing Keys
  • Impact on Users and Required Actions
  • Manual GPG Validation Users
  • Firefox RPM Users
  • What You Should Do

Details of the Incident

The compromised subkey was specifically utilized to sign Linux tarballs, RPM packages, and associated checksum files for Firefox and Thunderbird releases. Mozilla has confirmed that the incident’s scope was limited, affecting only a subset of users, and critically, there is no evidence to suggest that unauthorized parties accessed or copied the key during its presence in the repository.

An internal review of audit logs revealed that access to the private GitHub repository was strictly confined to a small, authorized internal Mozilla team. Furthermore, every individual with repository access already possessed legitimate authorization to access the signing key through established, secure channels. Despite the absence of malicious access, Mozilla proactively revoked the compromised signing key to mitigate any potential future risks and has implemented enhanced safeguards to prevent similar key-handling errors.

Importance of GPG Signing Keys

GPG signing keys are a foundational component of software supply-chain security. They enable users, package managers, and system administrators to verify the authenticity and integrity of downloaded software, ensuring that Firefox and Thunderbird files originate from Mozilla and have not been tampered with post-release. A leaked private signing subkey, even without evidence of misuse, theoretically poses a risk by allowing an attacker to create seemingly legitimate, yet malicious, software packages. The revocation effectively neutralizes this potential threat by invalidating the subkey’s ability to sign trusted future releases.

Impact on Users and Required Actions

The majority of Firefox and Thunderbird users are not required to take any immediate action. Standard browser installations and automatic update processes are designed to handle such key rotations seamlessly, without interruption.

Manual GPG Validation Users

Users who manually validate Mozilla release signatures with GPG must import the newly published signing key. They also need to import the revocation certificate for the previous key. Mozilla advises that releases signed with the revoked key may no longer validate after the revocation is imported, which is standard GPG behavior.

Firefox RPM Users

Firefox RPM users may need to take specific actions depending on their Linux distribution. Fedora 43 and newer systems are expected to automatically download the updated signing key during their next software update cycle. Users should verify that the displayed subkey fingerprint matches 827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3 before accepting the import.

Conversely, older Fedora releases (Fedora 42 and earlier), as well as systems running RHEL, Rocky Linux, AlmaLinux, openSUSE, and SUSE, do not automatically replace the old key. Administrators on these affected systems may encounter package update failures, with messages indicating incorrect GPG keys, failed signature verification, or missing trusted keys. These users must first remove the outdated RPM signing key, then import Mozilla’s new replacement key, and finally refresh their package metadata.

Mozilla has identified the new primary GPG key fingerprint as 14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353. This new signing subkey is set to expire on 2028-08-05. The public key and the revocation for the old key are accessible via Firefox Nightly KEY files, keys.openpgp.org, and Mozilla’s officially published key material.

This incident underscores the persistent challenge of securing cryptographic material within software supply chains, emphasizing that even internal exposures within restricted environments necessitate prompt and decisive action to maintain trust and security.

What You Should Do

  • Most Users: No immediate action is required. Your browser and operating system should handle the key rotation automatically.
  • Users Manually Validating GPG Signatures: Import the new signing key and the revocation certificate for the old key from Mozilla’s official sources.
  • Fedora 43+ RPM Users: Verify the new subkey fingerprint (827E 6586 0867 9618 CD34 9F93 678E 455D 7676 7AA3) during your next update.
  • Older Fedora, RHEL, Rocky Linux, AlmaLinux, openSUSE, SUSE RPM Users: Manually remove the old RPM signing key, import the new Mozilla key (14F2 6682 D091 6CDD 81E3 7B6D 61B7 B526 D98F 0353), and refresh your package metadata to avoid update failures.
  • Stay Informed: Regularly check official Mozilla security advisories for any further updates or instructions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurity

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Vulnerability in Emerson Controllers Lets Attackers Spoof Temperatures

Next Post

Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
US SOCs Combat Alert Fatigue: Strategies for Cybersecurity Noise Reduction
August 11, 2026
Critical Windows PnP Vulnerability Lets Attackers Gain SYSTEM Access
August 11, 2026
ClickFix Users Exposed to Malware via Polygon Blockchain Infrastructure
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us