MOZILLA has issued a new GPG signing subkey for Firefox and Thunderbird after the previous key was accidentally exposed in a GitHub repository. This exposure posed a risk of supply chain attacks, allowing malicious actors to create valid signatures on harmful files. Although the compromised key was stored in a private repository with restricted access, Mozilla decided to revoke it as a precaution and implement safeguards against future incidents.
Users generally do not need to take action, but those who verify GPG signatures or use Firefox RPM packages should follow provided instructions to import the new key.