Post #4507945
2026-08-11 16:08 UTC
Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it leaked to a private repo.
It is marked compromised, so past signatures no longer verify.
Verify by hand or ship Mozilla RPMs? Import the new key.
https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked
#SupplyChain #DataBreach #Linux #infosec
Replies (0)
No replies.