“Mozilla has revoked a cryptographic key used to sign Firefox and Thunderbird releases after discovering someone had accidentally committed an unencrypted copy of the private key to a GitHub repository.”
An unencrypted private signing key, committed to a repo. Mozilla says it found no evidence anyone accessed it, which is what you say when you lack the logs to prove otherwise. They also will not say how long it sat there or how it got there. The organization that lectures the rest of the industry about security did not have a pre-commit check covering its own release key.