Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days on the annual plan.Learn More
MERENA
Advisory Alert

Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub

Mozilla replaced a security key used to verify some Firefox and Thunderbird download files after an unprotected copy was accidentally stored in a private code repository. Most people are not affected, but people who manually downloaded certain Linux versions should be extra careful to get software only from official Mozilla sources.


Who is at risk

People most at risk are Linux users and system administrators who manually download or install Firefox or Thunderbird files, especially package files or checksum files, outside of standard app stores or trusted update systems.

What to watch for

Watch for browser or email app downloads that come from unofficial websites, fail verification checks, or seem different from normal update behavior.

What to do

If you downloaded Firefox or Thunderbird for Linux manually, re-download it from Mozilla’s official website or your trusted Linux software source and install the latest available version.