Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Mozilla Issues New Firefox GPG Key Following Exposure

0
Medium
News
Published: 08/11/2026 (08/11/2026, 06:16:01 UTC)
Source: SecurityWeek

Description

Mozilla revoked a Firefox and Thunderbird GPG signing subkey after it was inadvertently exposed in a private GitHub repository accessible only to a limited group of developers. The exposed key could have allowed an attacker to create valid signatures on malicious software artifacts, posing a supply chain risk. Mozilla's audit found no evidence of unauthorized access to the key. Most users do not need to take action, but those verifying GPG signatures or using Firefox RPM packages should update to the new key. Mozilla has implemented additional protections to prevent similar incidents.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/11/2026, 06:26:19 UTC

Technical Analysis

Mozilla accidentally committed an unencrypted GPG signing subkey used for Firefox and Thunderbird artifacts to a private GitHub repository. Although the repository was restricted to a small group of developers who already had access to the key, this exposure posed a risk that an attacker could sign malicious files to distribute them as authentic software. Mozilla conducted an audit and found no evidence of unauthorized access. To mitigate any potential risk, Mozilla revoked the exposed key and issued a new one, providing instructions for users who manually verify signatures or use RPM packages. Additional safeguards have been added to prevent recurrence.

Potential Impact

If exploited, the exposed GPG signing key could have enabled attackers to sign malicious Firefox and Thunderbird software artifacts, potentially facilitating supply chain attacks by distributing malicious software appearing authentic. However, the exposure was limited to a private repository with restricted access, and no unauthorized access was detected. Most users are unaffected, but those manually verifying signatures or using RPM packages may need to update keys.

Defensive Guidance

Mozilla has revoked the exposed GPG signing subkey and issued a new one. Users who manually verify GPG signatures should import the new key and the revocation for the old key. Users of Firefox RPM packages should follow Mozilla's detailed instructions for updating. Mozilla has also implemented additional protections to prevent similar key exposures in the future. Most users do not need to take any action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/mozilla-issues-new-firefox-gpg-key-following-exposure/","fetched":true,"fetchedAt":"2026-08-11T06:26:13.196Z","wordCount":1073}

Threat ID: 6a7ac085bf8831d5393f947f

Added to database: 08/11/2026, 06:26:13 UTC

Last enriched: 08/11/2026, 06:26:19 UTC

Last updated: 08/12/2026, 02:13:37 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses