The human risk platform that shapes employee behavior—automatically, in real time, right where people work. Cut risk. Sharpen habits. Build resilience.
Microsoft 365 accounts are being targeted with OAuth device code phishing, avoiding passwords and MFA to steal session tokens. We break down the attack and share a short, free, downloadable video you can send to employees.
Watch now: https://t.co/MbK8o7RLp6
Myth: younger generations are better at cybersecurity.
Reality: password habits say otherwise.
“123456” is still the most common password across generations, per @NordPass + @NordStellar.
Strong, unique passwords + MFA still matter. A lot.
Resources to protect your data 👇
Will 2026 be the year #cybersecurity finally masters behavior change?
Nicole Jiang of @FableSecurity says #security will adopt #Adtech tactics—using real-time signals & personalized nudges to turn "weak links" into strong defenses.
Read: https://t.co/m2bNUzrFTl
#predictions
And on the last day of Riskmas, we leave you with this: some risks travel together, creating toxic combinations that quietly amplify exposure.
So, find the overlap, prioritize the toxic combos, and zap risk.
Read now: https://t.co/2l9AMG53Rn
Technically Christmas is over. But Riskmas is still in full swing.
In our second-to-last blog of the series, we focus on how important targeting is in human risk campaigns.
Learn how targeted campaigns have better engagement and lead to lasting change: https://t.co/1YGgMIQV7G
Curious what this means for security teams next year?
Read Fable CEO Nicole Jiang’s take on what will change in cybersecurity in 2026 in Cyberwire’s article: https://t.co/fla60wlecp
Security tends to treat human behavior as immutable. In 2026, that'll change.
Cybersecurity is adapting to what other industries have known for years: behavior changes when the message is targeted, relevant, and timely.
The shift is starting, and we’re pushing it forward. 🧵
Metrics should do more than decorate dashboards.
Real risk involves behavior, context, speed, and durability. Not vanity metrics like phishing click rates or training completions.
More details in today’s post: https://t.co/HECUJQk6kX
Not all human risks fly solo. When two or more risks overlap more than you’d expect by chance, we call that a toxic combination.
Learn more about toxic combos, risk lift, and how this info can help your targeted behavior campaigns 👉
Who’s really pushing the limits with generative AI?
Tech teams. By a lot.
Our research shows employees aren’t just playing around, they’re uploading real code, documents, and potentially sensitive work.
Innovation moves fast. It’s time to help risk guardrails keep up.
You fixed the behavior. 🎉
But did it stick?
Behavior decay reveals how fast people drift back to risky habits once a campaign ends.
👉 Lasting change needs relevant guidance + ongoing monitoring before the risk comes back.
Check out day 7 of riskmas to learn more. ➡️
Phishing campaigns on autopilot? Yes, please.
Recurring phishing simulations in Fable let you automate campaigns for up to a year—no constant setup, no busywork—so your team can focus on the strategic stuff.
Read more: https://t.co/13N36GPyBt
From riskmas to risqué-mas, we’ve learned a lot this holiday season.
An uncomfortable and clear reminder from the Mixpanel breach: Pornhub data exposure can quickly turn into a human and workplace security issue.
Full breakdown + a free <2-min video below 👇