Wire · technology
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 11 August 2026 · Fusion42 review
Mozilla revoked a Firefox signing key after an unencrypted copy was mistakenly uploaded to GitHub, raising concerns about code signing security. This incident highlights risks in open source key management and the need for safer key handling.
This Wire brief sits within Fusion42's coverage of Software, and 2 sources have reported it between 11 Aug 2026 and 12 Aug 2026.
◆ ◆ The Wire takeaway
Your open source project now has a clear red flag on key security; you must urgently tighten how signing keys are stored and accessed to keep your builds trustworthy. Attackers will target leaked or poorly secured keys, turning your infrastructure against itself.
◆ Coverage
2 sources · first reported 11 Aug 2026 · latest 12 Aug 2026
◆ Related on Wire
◆ Topics