← All reports

Mozilla's decision to rotate its GPG signing subkey for Firefox and Thunderbird was a response to a previous subkey leak.

CybersecuritySoftware DevelopmentAug 11, 2026score 2.282 posts · 45 replies across 2 instances
Mozilla updated its GPG signing subkey for Firefox and Thunderbird after a previous subkey was accidentally exposed in a private GitHub repository. The update affects Linux tarballs, RPM packages, and checksum files.

Claims

Mozilla's decision to rotate its GPG signing subkey for Firefox and Thunderbird was a response to a previous subkey leak.
Parent: CybersecurityEntity: GPG Key ManagementImpact: negativeDate: Aug 11, 2026Target: Mozilla's GPG key management practices

Source posts

@[email protected]
Enjoy those vibes, nerds. https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/ Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository.
38 boosts · 29 favs · 5 replies · Aug 11, 2026
@[email protected]
Mozilla rotates GPG signing subkey for official Firefox and Thunderbird releases after the previous one leaked (it was inadvertently committed to a private GitHub repository) https://blog.mozilla.org/security/2026/08/10/updated-gpg-key-for-signing-firefox-and-thunderbird-releases/
5 boosts · 0 favs · 0 replies · Aug 11, 2026