MERENA is now on Google Play. Check scams, breaches and passwords, and get clear next steps, right from your Android phone.Get the App
MERENA
Advisory Alert

Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub

Mozilla replaced a security key used to verify some Firefox and Thunderbird download files after an unprotected copy was accidentally stored in a private code repository. Most people are not affected, but people who manually downloaded certain Linux versions should be extra careful to get software only from official Mozilla sources.


Who is at risk

People most at risk are Linux users and system administrators who manually download or install Firefox or Thunderbird files, especially package files or checksum files, outside of standard app stores or trusted update systems.

What to watch for

Watch for browser or email app downloads that come from unofficial websites, fail verification checks, or seem different from normal update behavior.

What to do

If you downloaded Firefox or Thunderbird for Linux manually, re-download it from Mozilla’s official website or your trusted Linux software source and install the latest available version.