DefenseVector Weekly05/16/2026, 11:21:15 PMOne prompt, one calc.exe: the RCE that rewrites your agent's threat modelIssue #1: Microsoft's CVE-2026-26030 / CVE-2026-25592 shows a single injected prompt can open a shell on the host. Learn why the existing 3-layer blocklist failed and get a copy-paste 4-layer AST-allowlist defense template to ship today.