Mozilla revoked its Linux signing key because someone committed it to a private repo
2026-08-12Security
No external compromise, no evidence of misuse, and the key still had until March 2027 to run. Mozilla revoked it anyway — which is the right call, and a useful reference point for how a signing-key incident should read.