Product
Ruxie learned to think: Why our automation engine needed an AI brain

We've given Expel AI capabilities to Ruxie, our automation engine. Here's how it works, and how it benefits our customers.

Data & research | 4 min read
New research reveals the “language barrier” holding back cybersecurity investment

We surveyed 300 security and finance leaders to find where collaboration breaks down. The problem isn't effort—it's structural misalignment.

Product | 4 min read
New Expel AI upgrade: “Pop the hood” on our detection strategies

Expel added new AI-generated descriptions to our detection rules, written in plain English, to improve transparency and understanding.

SOC | 2 min read
On the radar: Weeding out XMRig

XMRig is a cryptocurrency miner considered less malicious than other threats, but it's still worth prioritizing.

Current events | 7 min read
Our cybersecurity predictions for 2026

Our experts and leaders are sharing their predictions for cybersecurity trends in 2026 to help you start strategizing.

SOC | 7 min read
Why building a 24×7 SOC is getting harder (and what actually works instead)

The math on building an in-house SOC has changed, including the real costs, why retention is brutal, and what actually works.

Company news | 4 min read
2025 Wrapped: A year in review at Expel

Expel is rounding out 2025 with a recap of our best moments of the year. Stay tuned for more to come in 2026 because we aren't slowing down.

SOC | 6 min read
Stories from the SOC: The second coming of Shai Hulud

A new variant of the Shai Hulud worm has been discovered, and we're sharing effective approaches to remediate the threat.

Company news | 6 min read
Why we started the Job Security Podcast: building community in cybersecurity

Announcing "The Job Security Podcast" sponsored by Expel. We're focusing on creating and sharing stories with the cybersecurity community.

Product | 2 min read
More SIEM flexibility: Expel MDR adds support for Panther

Expel announces support for Panther's cloud-native SIEM as the latest in our long list of advanced integrations.

Threat intel | 5 min read
Patch Tuesday: December 2025 (Expel’s version)

This month we're highlighting top critical vulnerabilities, including three zero-day and three critical remote code execution vulnerabilities.

Rapid response | 2 min read
Active exploitation notice: React2Shell critical vulnerability (CVE-2025-55182)

A React2Shell critical vulnerability (CVE-2025-55182) is under active exploitation. Here's what you need to know and how to identify it.

MDR | 4 min read
Expel + AWS Security Hub: Turning findings into action

Expel is a partner for the new AWS Security Hub. We layer detection engineering on top of its finding to solve prioritization problems.