Cybersecurity
Mozilla Revokes Signing Key for Firefox and Thunderbird After Key Exposure
Mozilla has revoked the cryptographic key for Firefox and Thunderbird on Linux following its accidental exposure on GitHub.

Mozilla has announced the revocation of the cryptographic signing key used for Firefox and Thunderbird releases on Linux. This decision follows the accidental exposure of an unencrypted copy of the key, which was mistakenly committed to one of the company's private code repositories on GitHub.
The signing key is essential for verifying that downloads of the browsers are legitimate and have not been tampered with. The revocation of the key requires Mozilla to update its release verification process and to inform users and Linux distributions of the change.
According to reports, Mozilla's audit logs indicated no unexpected access during the incident. However, the company must now address any potential implications from the key's exposure and ensure the integrity of its software distribution.