Mozilla Firefox and Thunderbird Linux signing key remediation
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Mozilla's Firefox and Thunderbird Linux signing key revocation leaves some Linux verification and RPM updates dependent on importing the new key and removing trust in the old one. Users who verify signatures manually or install from Mozilla RPM packages may need manual remediation to restore successful verification and updates.
Related Happenings
Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure
Security Tool/Service
H score11
First: 11.08.2026 15:04
Last: 11.08.2026 15:04
Sources 1
How related:
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories.
About this happening:
Mozilla revoked and replaced the Firefox and Thunderbird Linux signing key, disrupting verification of older signed downloads and some RPM package installs until t...
Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure
Security Tool/ServiceHow related: Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories.
About this happening: Mozilla revoked and replaced the Firefox and Thunderbird Linux signing key, disrupting verification of older signed downloads and some RPM package installs until t...
Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft
Technical Analysis
H score30
First: 08.08.2026 11:03
Last: 08.08.2026 11:03
Sources 1
About this happening:
PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastm...
Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft
Technical AnalysisAbout this happening: PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastm...
Mozilla Firefox 151.0.3 security update for CVE-2026-10702
Security Patch Release
H score30
First: 29.07.2026 14:57
Last: 29.07.2026 14:57
Sources 1
About this happening:
Mozilla released Firefox 151.0.3 to fix CVE-2026-10702, a High-severity browser flaw that could be triggered by visiting a malicious webpage. The update closes an...
Mozilla Firefox 151.0.3 security update for CVE-2026-10702
Security Patch ReleaseAbout this happening: Mozilla released Firefox 151.0.3 to fix CVE-2026-10702, a High-severity browser flaw that could be triggered by visiting a malicious webpage. The update closes an...
Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)
Vulnerability
H score31
First: 29.07.2026 14:57
Last: 29.07.2026 14:57
Sources 1
About this happening:
Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer proc...
Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)
VulnerabilityAbout this happening: Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer proc...
Mozilla Firefox 152.0.6 security update (CVE-2026-15718, CVE-2026-15719)
Security Patch Release
H score41
First: 15.07.2026 16:18
Last: 15.07.2026 16:18
Sources 1
About this happening:
Mozilla's Firefox 152.0.6 update fixes two critical flaws after exploit code was published, reducing risk for users running unpatched browsers. The release remediates...
Mozilla Firefox 152.0.6 security update (CVE-2026-15718, CVE-2026-15719)
Security Patch ReleaseAbout this happening: Mozilla's Firefox 152.0.6 update fixes two critical flaws after exploit code was published, reducing risk for users running unpatched browsers. The release remediates...
Timeline
-
11.08.2026 15:04 2 articles · 2h ago
Mozilla Firefox and Thunderbird Linux signing key remediation
Initial DisclosureAn unencrypted copy of Mozilla's signing key was committed to a private repository, and Mozilla revoked the old subkey and published a replacement. The first impacted systems were Linux downloads and RPM-based update flows that depended on the old signing material.
Show sources
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo — thehackernews.com — 11.08.2026 15:04
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo — thehackernews.com — 11.08.2026 15:04