Mozilla Revokes Firefox Signing Key After Unencrypted Subkey Was Committed to GitHub
Mozilla replaced a security key used to verify some Firefox and Thunderbird download files after an unprotected copy was accidentally stored in a private code repository. Most people are not affected, but people who manually downloaded certain Linux versions should be extra careful to get software only from official Mozilla sources.
Who is at risk
People most at risk are Linux users and system administrators who manually download or install Firefox or Thunderbird files, especially package files or checksum files, outside of standard app stores or trusted update systems.
What to watch for
Watch for browser or email app downloads that come from unofficial websites, fail verification checks, or seem different from normal update behavior.
What to do
If you downloaded Firefox or Thunderbird for Linux manually, re-download it from Mozilla’s official website or your trusted Linux software source and install the latest available version.
