ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
MEDIUM Open Source

Mozilla rotates Firefox and Thunderbird GPG signing key after GitHub exposure

Source headline: Mozilla updates GPG signing key for Firefox releases after exposure

Threat level Medium
Signal strength 65/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Mozilla says it updated the GPG key used to sign Firefox and Thunderbird release packages. The previous signing key was accidentally exposed on GitHub. By rotating the key, Mozilla aims to reduce trust risks for the affected distribution pipeline. Users who download Firefox or Thunderbird should continue relying on Mozilla’s official release and verification instructions. The change mainly impacts cryptographic trust for release signatures rather than normal browsing. No specific compromise details are mentioned, but the incident warrants key rotation.

Recommended Action

Review source details and prioritize according to asset exposure.

Topics

#supply-chain #firefox #gpg #mozilla #release-signing #thunderbird
Original reporting BleepingComputer Mozilla updates GPG signing key for Firefox releases after exposure
Open original source