Data & research
Expel Quarterly Threat Report, Q2 2025: Q2 by the numbers

Part I of our Quarterly Threat Report summarizes key findings and stats from Q2 of 2025. Learn what to focus on right now.

Product | 4 min read
When your keys go missing: getting real about identity threats

Expel updated our threat alerts to be clearer, so you understand precisely what's happening with credential theft and account compromise.

Product | 5 min read
That’s not MDR, it’s a scapegoat

Discover why outsourcing alert triage falls short and how a human-AI collaborative approach can improve cybersecurity outcomes.

Threat intel | 2 min read
An important update (and apology) on our PoisonSeed blog

An important update and apology on the Expel blog, for a blog we published on PoisonSeed on July 17, 2025.

Product | 5 min read
Explore Expel’s auto remediations: Disable access key

In this series, we explore Expel's auto remediations so you understand how they work. Let's explore disable access key.

Data & research | 5 min read
Expel Quarterly Threat Report, Q2 2025: Threat intel recap

Here's a refresher on the threat intel we shared throughout the second quarter of 2025. Catch up on what you missed.

MDR | 4 min read
The hidden costs of ‘cheaper’ security

Beware of the hidden costs of "cheaper" security, and know what you should ask and pay attention to before switching MDR providers.

Rapid response | 2 min read
Update on the SharePoint ToolShell vulnerability exploitation (CVE-2025-53770)

Over the weekend, a zero-day vulnerability for SharePoint 16.0.0.0 and earlier versions was targeted. Here's what you need to know.

Data & research | 5 min read
Expel Quarterly Threat Report, Q2 2025: Q2 by the numbers

Part I of our Quarterly Threat Report summarizes key findings and stats from Q2 of 2025. Learn what to focus on right now.

Product | 3 min read
Expel’s guiding principles: Building AI and automation into the foundation of our MDR

Expel has three guiding principles that guide how AI & automation are used as the foundation of our SecOps platform, Expel Workbench™.

Product | 6 min read
Explore Expel’s auto remediations: Disable user account

In this series, we explore Expel's auto remediations so you understand how they work. Let's explore disable user account.

SOC | 6 min read
PoisonSeed downgrading FIDO key authentications to ‘fetch’ user accounts

Attack group PoisonSeed has recently found a way to downgrade FIDO key authentication in a new social engineering tactic via cross-device sign-in.

MDR | 7 min read
Alert fatigue, burnout, turnover: lather, rinse, repeat

Many security orgs are trapped in a difficult cycle. Alert fatigue causes service quality degradation and fuels burnout. Rinse & repeat.