Supply chain

Mozilla issues new GPG key after accidental exposure

Firefox web browser under magnifying glass. Firefox is a free and open-source web browser developed by the Mozilla Foundation.

Mozilla announced Monday that it has issued a new GPG signing subkey for Firefox and Thunderbird artifacts following the accidental exposure of a previous key in a GitHub repository, as reported by Security Week.

The exposed GPG key was used to sign artifacts like Linux tarballs and RPM packages. While an unencrypted copy was inadvertently committed to a private GitHub repository, Mozilla stated there was no evidence of unauthorized access. To mitigate potential supply chain risks, where an attacker could sign malicious files with the exposed key, Mozilla has revoked the old key and issued a new one.

Most users do not need to take action, but those who manually verify GPG signatures or use Firefox RPM packages should follow updated instructions.

Source: Security Week

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds