MDR
The Complimentary 2025 Gartner® Market Guide for Managed Detection & Response Services is here (and Expel is recognized, again)

The 2025 Gartner® Market Guide for Managed Detection & Response Services is here, and Expel is recognized as a Representative Vendor again.

Threat intel | 3 min read
Expel Quarterly Threat Report, Q3 2025: Threat intel recap

Here's a refresher on the threat intel we shared throughout the third quarter of 2025. Catch up on what you missed.

Threat intel | 4 min read
Expel Quarterly Threat Report, Q3 2025: Q3 by the numbers

Part I of our Quarterly Threat Report summarizes key findings and stats from Q3 of 2025. Learn what to focus on right now.

Threat intel | 6 min read
Certified OysterLoader: Tracking Rhysida ransomware gang activity via code-signing certificates

Rhysida ransomware gang has been using code-signing certificates to validate their malware campaigns repeatedly. Here's the latest.

SOC | 4 min read
Stories from the SOC: The curious case of termination notices

Our new "Stories from the SOC" series shares real-world attacks we've seen and stopped. This one covers a phishing attack on a university.

Threat intel | 4 min read
Beyond alert management: How threat intelligence actually helps your SOC

We're expanding our dedicated threat intel function to provide our customers with smarter, faster, threat intelligence they can use.

Rapid response | 2 min read
Security alert: WSUS remote code execution vulnerability

A critical WSUS vulnerability (CVE-2025-59287) is under active exploitation. Learn what happened, why to care, and how to protect your org.

Threat intel | 7 min read
Along for the ride: When legitimate software becomes a signed malware loader

Analyzing a highly evasive malware loader that exploits legitimate, signed Greenshot software through DLL sideloading. See our detailed technical analysis.

Threat intel | 2 min read
Patch Tuesday: October 2025 (Expel’s version)

This month, we're highlighting top critical vulnerabilities, including six zero-day vulnerabilities, and one in Cisco IOS.

Current events | 2 min read
Cybersecurity Awareness Month: Good reminders for the entire year

October is Cybersecurity Awareness Month. Here are four tips for staying secure this month (and the rest) at work and at home.

MDR | 3 min read
The Complimentary 2025 Gartner® Market Guide for Managed Detection & Response Services is here (and Expel is recognized, again)

The 2025 Gartner® Market Guide for Managed Detection & Response Services is here, and Expel is recognized as a Representative Vendor again.

Threat intel | 6 min read
Cache smuggling: When a picture isn’t a thousand words

We recently observed an innovative campaign using the ClickFix attack tactic for cache smuggling. Here's what you need to know.

MDR | 3 min read
Stop counting integrations. Start counting what matters.

With integrations and security, quantity is not the same as quality. Integration counts are a vanity metric that make you less secure.