Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure

Security Tool/Service
First reported
Last updated
Happening score
H score 11
2 unique sources, 2 articles

Summary

Hide ▲

Mozilla revoked and replaced the Firefox and Thunderbird Linux signing key, disrupting verification of older signed downloads and some RPM package installs until the new key is installed. The change matters because the retired key is used to confirm Linux tarballs came from Mozilla and were not tampered with. Users who verify signatures manually, and some Linux distribution package flows, must switch to the replacement key to restore trust checks.

Related Happenings

Mozilla Firefox and Thunderbird Linux signing key remediation

Advisory/Mitigation
H score18 First: 11.08.2026 15:04 Last: 11.08.2026 15:04 Sources 1

How related: Anyone who checks signatures by hand must import the new key plus the revocation for the old one. Anyone installing Firefox from Mozilla's RPM packages may hit a failed update and have to swap the key manually.

About this happening: Mozilla's Firefox and Thunderbird Linux signing key revocation leaves some Linux verification and RPM updates dependent on importing the new key and removing trust...

Mozilla Firefox 151.0.3 security update for CVE-2026-10702

Security Patch Release
H score30 First: 29.07.2026 14:57 Last: 29.07.2026 14:57 Sources 1

About this happening: Mozilla released Firefox 151.0.3 to fix CVE-2026-10702, a High-severity browser flaw that could be triggered by visiting a malicious webpage. The update closes an...

Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)

Vulnerability
H score31 First: 29.07.2026 14:57 Last: 29.07.2026 14:57 Sources 1

About this happening: Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer proc...

Mozilla Firefox 152.0.6 security update (CVE-2026-15718, CVE-2026-15719)

Security Patch Release
H score41 First: 15.07.2026 16:18 Last: 15.07.2026 16:18 Sources 1

About this happening: Mozilla's Firefox 152.0.6 update fixes two critical flaws after exploit code was published, reducing risk for users running unpatched browsers. The release remediates...

Microsoft Exchange Online blocks legacy TLS for POP3 and IMAP4 starting July 2026

Security Tool/Service
H score11 First: 28.04.2026 16:18 Last: 28.04.2026 16:18 Sources 1

About this happening: Microsoft will block TLS 1.0 and TLS 1.1 for POP3/IMAP4 access to Exchange Online in July 2026, which could break legacy mail clients and embedded devices...

Timeline

  1. 11.08.2026 15:04 3 articles · 2h ago

    Mozilla revokes and replaces Firefox and Thunderbird Linux signing key after private repo exposure

    Initial Disclosure

    Mozilla pulled the Firefox and Thunderbird Linux signing key after an unencrypted copy was committed to a private repository. The change forces signature verifiers and some RPM users to move to the replacement key before old downloads continue to validate.

    Show sources