[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2DTUAfBuG5UAv0jpTxfqGXvEYs0USaQY5oP__GJ9cLs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"d0ab5779-0891-4337-bc3c-60997749f60f","mozilla-gpg-key-exposed-in-private-github-repo-supply-chain-near-miss","ba75c104-6a96-4ae7-bac8-0786bc3cb244","Mozilla GPG Key Exposed in Private GitHub Repo — Supply Chain Near-Miss","Mozilla's GPG signing subkey for Firefox and Thunderbird was inadvertently committed to a private GitHub repository, creating a direct supply chain risk: if an attacker had discovered and exfiltrated the key, they could have signed malicious artifacts that appeared legitimate to end users. Although Mozilla found no evidence of unauthorized access, the incident highlights how secrets management failures can silently undermine software integrity guarantees. Cryptographic signing keys are high-value targets because they form the root of trust for software distribution pipelines. The rapid revocation and replacement of the key, combined with added protections, demonstrates appropriate incident response — but the exposure should never have occurred in the first place.","**Immediate actions:**\n- Audit all repositories (public and private) for committed secrets, credentials, and cryptographic key material using automated secret-scanning tools.\n- Rotate and revoke any exposed signing keys immediately and notify downstream consumers of the new trusted key.\n\n**Long-term improvements:**\n- Store cryptographic signing keys exclusively in dedicated secrets management systems (e.g., HashiCorp Vault, AWS KMS, HSMs) and never in source control.\n- Enforce pre-commit hooks and CI\u002FCD pipeline checks that block commits containing key material, tokens, or other secrets before they reach any repository.\n- Apply strict least-privilege access controls to repositories that touch build and release pipelines, ensuring only authorized personnel can read or write signing-related assets.\n\n**Detection & monitoring measures:**\n- Enable GitHub Advanced Security secret scanning alerts (or equivalent) on all private repositories to receive real-time notifications of exposed credentials.\n- Implement continuous monitoring and alerting on cryptographic key usage logs to detect anomalous signing activity that could indicate key compromise.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4 — Secure Configuration of Enterprise Assets","CIS Control 6 — Access Control Management","CIS Control 16 — Application Software Security","NIST SP 800-53 SC-12 — Cryptographic Key Establishment and Management","NIST SP 800-53 AC-3 — Access Enforcement","NIST SP 800-53 SI-12 — Information Management and Retention","NIST SP 800-161 — Supply Chain Risk Management Practices","NIST CSF PR.DS-2 — Data-in-Transit Protection","NIST CSF ID.SC-4 — Supply Chain Risk Assessment","SLSA Supply Chain Levels for Software Artifacts — Build Integrity Requirements","GDPR Article 32 — Security of Processing (where applicable to EU user data integrity)","published","2026-08-11T08:20:40.056668+00:00","2026-08-11T08:20:39.58+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.securityweek.com\u002Fmozilla-issues-new-firefox-gpg-key-following-exposure\u002F","mozilla-issues-new-firefox-gpg-key-following-exposure-9d308e","Mozilla Issues New Firefox GPG Key Following Exposure",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]