Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty

    August 11, 2026

    What We Know About the Earthquake in Colombia

    August 11, 2026

    A question for Burnham as he tours the country: how to reduce the magnetic pull of London? | Peter Hetherington

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty
    • What We Know About the Earthquake in Colombia
    • A question for Burnham as he tours the country: how to reduce the magnetic pull of London? | Peter Hetherington
    • Maga ignores the many meanings of Mount Rushmore
    • Why recovery readiness has become the new standard for cyber resilience
    • webAI Releases TwIL-LM: A 1.7B and 3B Formal-Logic Model Family for Autoformalization on Local Hardware
    • Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine
    • South Korea puts crypto exchanges on a seven-day clock under new seizure rules
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Mozilla Issues New Firefox GPG Key Following Exposure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Mozilla announced on Monday that it has issued a new GPG signing subkey used for some Firefox and Thunderbird artifacts after the previous key was accidentally exposed in a GitHub repository.

    In general, if a GPG private signing key used for software releases is exposed, an attacker who obtains it could create valid signatures on malicious files.

    This creates a supply chain attack risk: the attacker could distribute modified or malicious versions of the software that appear authentic. Successful exploitation would still require a way to deliver the signed files to users, for instance via a compromised mirror, an alternate download path, or social engineering.

    However, in Mozilla’s case, the potential impact is mitigated by several factors. 

    The exposed GPG key was used to sign Firefox and Thunderbird artifacts such as Linux tarballs, RPM packages, and checksum files. An unencrypted copy of the key was inadvertently committed to a GitHub repository, but it was a private repository accessible only to a small group of Mozilla developers who already had access to the key via other means.

    “Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository,” Mozilla said.

    Advertisement. Scroll to continue reading.

    Nevertheless, the organization has decided to revoke the exposed key and issue a new one. In addition, it has added protections to prevent similar incidents in the future. 

    Mozilla noted that most users do not need to take any action. Users who manually verify GPG signatures will have to import the new key and revocation for the old one. In addition, those who use Firefox RPM packages may need to take some steps — Mozilla has shared detailed instructions for them.

    It’s not surprising that Mozilla has decided not to take any chances. Given the well-documented surge in software supply chain attacks over the past year, organizations are increasingly rotating signing keys at the first sign of potential exposure.

    Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

    Related: Multiple Jscrambler Packages Impacted by Supply Chain Attack

    Related: North Korean Hackers Target Open Source Developers in Supply Chain Attacks

    exposure Firefox GPG issues key Mozilla
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

    New Jersey, Alabama Join States Targeted in Water Cyberattacks

    OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

    ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    Hackers breached a small Polish energy plant via private APN last year

    ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty

    August 11, 2026

    What We Know About the Earthquake in Colombia

    August 11, 2026

    A question for Burnham as he tours the country: how to reduce the magnetic pull of London? | Peter Hetherington

    August 11, 2026

    Maga ignores the many meanings of Mount Rushmore

    August 11, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Katriona O’Sullivan’s story of growing up in poverty is one that we can all learn from | Poverty

    August 11, 2026

    What We Know About the Earthquake in Colombia

    August 11, 2026

    A question for Burnham as he tours the country: how to reduce the magnetic pull of London? | Peter Hetherington

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.