Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.
However, in a Monday blog post, it noted that the risk of a supply chain attack in which threat actors could distribute malicious installers signed with the exposed key is low because only a limited number of individuals had access to the GitHub repository.
Additionally, Mozilla has yet to find evidence that the previous GPG key was accessed by unauthorized parties while being exposed.
After discovering the incident, the organization revoked the key used to sign Linux tarballs, RPM packages, and checksum files, and has taken measures to prevent similar issues in the future.
"Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository," it noted.
Source: BleepingComputer