Mozilla Revokes Firefox GPG Key After GitHub Exposure

TL;DR. Mozilla revoked a Firefox and Thunderbird GPG signing subkey after its accidental exposure in a GitHub repository. - The exposed key could allow attackers to sign malicious software, creating a supply chain risk. - Mozilla found no evidence of unauthorized access to the private repository. - Most users do not need action; those verifying GPG signatures must import the new key.

Sources

Back to QLANKR News