Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure
Security Tool/Service
Summary
Hide ▲
Show ▼
Mozilla revoked and replaced the Firefox and Thunderbird Linux signing key, disrupting verification of older signed downloads and some RPM package installs until the new key is installed. The change matters because the retired key is used to confirm Linux tarballs came from Mozilla and were not tampered with. Users who verify signatures manually, and some Linux distribution package flows, must switch to the replacement key to restore trust checks.
Related Happenings
Mozilla Firefox and Thunderbird Linux signing key remediation
Advisory/Mitigation
H score18
First: 11.08.2026 15:04
Last: 11.08.2026 15:04
Sources 1
How related:
Anyone who checks signatures by hand must import the new key plus the revocation for the old one. Anyone installing Firefox from Mozilla's RPM packages may hit a failed update and have to swap the key manually.
About this happening:
Mozilla's Firefox and Thunderbird Linux signing key revocation leaves some Linux verification and RPM updates dependent on importing the new key and removing trust...
Mozilla Firefox and Thunderbird Linux signing key remediation
Advisory/MitigationHow related: Anyone who checks signatures by hand must import the new key plus the revocation for the old one. Anyone installing Firefox from Mozilla's RPM packages may hit a failed update and have to swap the key manually.
About this happening: Mozilla's Firefox and Thunderbird Linux signing key revocation leaves some Linux verification and RPM updates dependent on importing the new key and removing trust...
Mozilla Firefox 151.0.3 security update for CVE-2026-10702
Security Patch Release
H score30
First: 29.07.2026 14:57
Last: 29.07.2026 14:57
Sources 1
About this happening:
Mozilla released Firefox 151.0.3 to fix CVE-2026-10702, a High-severity browser flaw that could be triggered by visiting a malicious webpage. The update closes an...
Mozilla Firefox 151.0.3 security update for CVE-2026-10702
Security Patch ReleaseAbout this happening: Mozilla released Firefox 151.0.3 to fix CVE-2026-10702, a High-severity browser flaw that could be triggered by visiting a malicious webpage. The update closes an...
Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)
Vulnerability
H score31
First: 29.07.2026 14:57
Last: 29.07.2026 14:57
Sources 1
About this happening:
Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer proc...
Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)
VulnerabilityAbout this happening: Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer proc...
Mozilla Firefox 152.0.6 security update (CVE-2026-15718, CVE-2026-15719)
Security Patch Release
H score41
First: 15.07.2026 16:18
Last: 15.07.2026 16:18
Sources 1
About this happening:
Mozilla's Firefox 152.0.6 update fixes two critical flaws after exploit code was published, reducing risk for users running unpatched browsers. The release remediates...
Mozilla Firefox 152.0.6 security update (CVE-2026-15718, CVE-2026-15719)
Security Patch ReleaseAbout this happening: Mozilla's Firefox 152.0.6 update fixes two critical flaws after exploit code was published, reducing risk for users running unpatched browsers. The release remediates...
Microsoft Exchange Online blocks legacy TLS for POP3 and IMAP4 starting July 2026
Security Tool/Service
H score11
First: 28.04.2026 16:18
Last: 28.04.2026 16:18
Sources 1
About this happening:
Microsoft will block TLS 1.0 and TLS 1.1 for POP3/IMAP4 access to Exchange Online in July 2026, which could break legacy mail clients and embedded devices...
Microsoft Exchange Online blocks legacy TLS for POP3 and IMAP4 starting July 2026
Security Tool/ServiceAbout this happening: Microsoft will block TLS 1.0 and TLS 1.1 for POP3/IMAP4 access to Exchange Online in July 2026, which could break legacy mail clients and embedded devices...
Timeline
-
11.08.2026 15:04 3 articles · 2h ago
Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure
Initial DisclosureMozilla pulled the Firefox and Thunderbird Linux signing key after an unencrypted copy was committed to a private repository. The change forces signature verifiers and some RPM users to move to the replacement key before old downloads continue to validate.
Show sources
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo — thehackernews.com — 11.08.2026 15:04
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo — thehackernews.com — 11.08.2026 15:04
- Mozilla updates GPG signing key for Firefox releases after exposure — www.bleepingcomputer.com — 11.08.2026 16:20