Varonis found a “Reprompt” attack that let a single link hijack Microsoft Copilot Personal sessions and exfiltrate data; Microsoft patched it in January 2026.
I tried four vibe-coding tools, including Cursor and Replit, with no coding background. Here's what worked (and what didn't).