Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla rotates GPG signing key for Firefox/Thunderbird after accidental GitHub exposure.
Summary
Mozilla has rotated its GPG signing key for Firefox and Thunderbird releases after an unencrypted copy was inadvertently committed to a private GitHub repository. While the risk of a supply chain attack is considered low due to limited access and no evidence of unauthorized access, users who manually verify signatures will need to update their systems. Mozilla has provided specific instructions for various Linux distributions.
Full text
Mozilla updates GPG signing key for Firefox releases after exposure By Sergiu Gatlan August 11, 2026 09:20 AM 0 Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. However, in a Monday blog post, it noted that the risk of a supply chain attack in which threat actors could distribute malicious installers signed with the exposed key is low because only a limited number of individuals had access to the GitHub repository. Additionally, Mozilla has yet to find evidence that the previous GPG key was accessed by unauthorized parties while being exposed. After discovering the incident, the organization revoked the key used to sign Linux tarballs, RPM packages, and checksum files, and has taken measures to prevent similar issues in the future. "Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository," it noted. "Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Access to the repository was limited to a small group within Mozilla, all of whom already had authorized access to the key through other means." While most users will not have to take any action after the GPG key's rotation, Mozilla says that users who manually verify GPG signatures must import the new signing key and the revocation for the old key. It also added that Linux users who install Firefox using RPM packages may need to manually update their systems and shared detailed instructions on what actions are required on systems running Fedora 43 and later, Fedora 42 and older, RHEL/Rocky/Almalinux, and openSUSE/SUSE-based distributions to continue receiving the latest Firefox updates. Since Thunderbird does not provide official RPM packages, no RPM-specific action is required for Thunderbird users. The new signing subkey expires August 5, 2028, and the new public key and revocation for the previous key are available through the latest Firefox Nightly KEY files and keys.openpgp.org. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: GitHub, PyPI add time-based defenses against supply chain attacksFakeGit campaign uses 7,600 GitHub repos to push SmartLoader malwareAsyncAPI npm packages infected with credential-stealing malwareNearly 300 GitHub repos pose as legit software to push malwareClean GitHub repo tricks AI coding agents into running malware