Threat intel
Planned failure: Gootloader’s malformed ZIP actually works perfectly

Gootloader malware contains a deliberately malformed ZIP archive to bypass detection, but can also be identified by its unique formatting.

Product | 2 min read
What we built: January 2026

Here's what Expel's product team shipped in January. This month, we're highlighting new webhooks for phishing and dark mode for Workbench.

Data & research | 4 min read
The quarterly meeting trap: why security and finance think they’re aligned (but aren’t)

There's a clear disconnect between CISOs and CFOs that can be partially resolved by better communication. Download the report to learn more.

Threat intel | 12 min read
ClearFake gets more evasive with new living off the land (LOTL) techniques

ClearFake's latest campaign uses fake CAPTCHAs and social engineering trick victims into installing malware, and it's getting more evasive.

Threat intel | 12 min read
Planned failure: Gootloader’s malformed ZIP actually works perfectly

Gootloader malware contains a deliberately malformed ZIP archive to bypass detection, but can also be identified by its unique formatting.

Threat intel | 5 min read
Patch Tuesday: January 2026 (Expel’s version)

We're highlighting five critical CVEs, and we're also recapping our vulnerability prioritization recommendations from 2025 to see how we did.

Data & research | 4 min read
New research reveals the “language barrier” holding back cybersecurity investment

We surveyed 300 security and finance leaders to find where collaboration breaks down. The problem isn't effort—it's structural misalignment.

Product | 4 min read
New Expel AI upgrade: “Pop the hood” on our detection strategies

Expel added new AI-generated descriptions to our detection rules, written in plain English, to improve transparency and understanding.

SOC | 2 min read
On the radar: Weeding out XMRig

XMRig is a cryptocurrency miner considered less malicious than other threats, but it's still worth prioritizing.

Current events | 7 min read
Our cybersecurity predictions for 2026

Our experts and leaders are sharing their predictions for cybersecurity trends in 2026 to help you start strategizing.

SOC | 7 min read
Why building a 24×7 SOC is getting harder (and what actually works instead)

The math on building an in-house SOC has changed, including the real costs, why retention is brutal, and what actually works.

Company news | 4 min read
2025 Wrapped: A year in review at Expel

Expel is rounding out 2025 with a recap of our best moments of the year. Stay tuned for more to come in 2026 because we aren't slowing down.

SOC | 6 min read
Stories from the SOC: The second coming of Shai Hulud

A new variant of the Shai Hulud worm has been discovered, and we're sharing effective approaches to remediate the threat.