Mozilla announced Monday that it has issued a new GPG signing subkey for Firefox and Thunderbird artifacts following the accidental exposure of a previous key in a GitHub repository, as reported by Security Week.The exposed GPG key was used to sign artifacts like Linux tarballs and RPM packages. While an unencrypted copy was inadvertently committed to a private GitHub repository, Mozilla stated there was no evidence of unauthorized access. To mitigate potential supply chain risks, where an attacker could sign malicious files with the exposed key, Mozilla has revoked the old key and issued a new one.Most users do not need to take action, but those who manually verify GPG signatures or use Firefox RPM packages should follow updated instructions.Source: Security Week
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
