Mozilla Issues New GPG Signing Key for Firefox After Accidental Exposure

Mozilla has issued a new GPG signing subkey for some Firefox and Thunderbird artifacts after the previous key was inadvertently exposed in a GitHub repository. While the potential impact is mitigated by several factors, the move addresses a supply chain attack risk where an attacker could create valid signatures on malicious files.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai