Your safety profile is now part of the free plan. Tell us what you use, and we'll customize your alerts and guidance to match your online life.Build My Profile
MERENA
Advisory Alert

Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub

Mozilla replaced a security key used to verify some Firefox and Thunderbird download files after an unprotected copy was accidentally stored in a private code repository. Most people are not affected, but people who manually downloaded certain Linux versions should be extra careful to get software only from official Mozilla sources.


Who is at risk

People most at risk are Linux users and system administrators who manually download or install Firefox or Thunderbird files, especially package files or checksum files, outside of standard app stores or trusted update systems.

What to watch for

Watch for browser or email app downloads that come from unofficial websites, fail verification checks, or seem different from normal update behavior.

What to do

If you downloaded Firefox or Thunderbird for Linux manually, re-download it from Mozilla’s official website or your trusted Linux software source and install the latest available version.