Threat intel
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.

Rapid response | 4 min read
ChainDrop: The Mini Shai Hulud npm worm’s latest wave hits keyv and cacheable

A self-propagating npm worm hit keyv, cacheable, and hundreds of dependent packages to steal CI/CD, cloud, and API credentials. Here's what to do now.

Product | 3 min read
Expel now covers the full AI attack surface

Expel is the top MDR provider covering the full AI attack surface: AI-powered attacks, employee misuse, and exposure inside AI systems. See what's live now.

Product | 3 min read
What we built: July 2026

In July, Expel launched six new threat hunts spanning the AI attack surface, for new features, and one integration update.

Threat intel | 2 min read
Expel’s Q2 2026 threat report: Identity’s back on top, and Teams phishing isn’t slowing down

Expel's Q2 2026 threat data: identity attacks jump to 68.1%, Teams phishing drives an endpoint spike, and a new supply chain worm hits cloud infrastructure.

Expel culture | 4 min read
Meet the Expletive: Josh Carter, SOC Manager

Meet Josh Carter, SOC manager at Expel. He's a self-taught multi-instrumentalist with a firm stance on pizza: triangles only.

Threat intel | 8 min read
When red teams go off the rails, who’s at fault?

Why do red team reports focus on tactics attackers rarely use? Expel's data reveals the misalignment—and a better model.

Threat intel | 6 min read
The feature that stops BYOVD (bring your own vulnerable driver)

BYOVD attacks beat driver blocklists every time. See how WDAC/App Control for Business—deployed via Active Directory—closes the gap for good.

Threat intel | 13 min read
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

CylindricalCanine is a new threat group within GoldenEyeDog, and they're actively using their malware for email phishing. Here's what you need to know.

Threat intel | 2 min read
Patch Tuesday: July 2026 (Expel’s version)

July's Patch Tuesday release includes a record-breaking 570 CVEs. These are the four we think need your attention now.

Rapid response | 2 min read
The “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePuffer

Analysis of agentic ransomware JadePuffer: human operator, LLM agent limits, and why fundamentals still protect defenders.

Product | 2 min read
What we built: June 2026

See what Expel shipped in June 2026, including two new threat hunts and updated CrowdStrike Falcon detection coverage.

Threat intel | 19 min read
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.