Cybersecurity briefing — 2026-06-08

A malicious Python package can now steal your CI secrets at install time, before a single import ever runs.