Threat intel
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.

MDR | 3 min read
The hidden cost of alert fatigue (and how agentic MDR fixes it)

Alert fatigue causes analysts to miss real threats—not from lack of skill, but from queue pressure. Here's how agentic MDR handles the volume.

Threat intel | 10 min read
Reading the certificate leaves: Understanding GoldenEyeDog’s teams—CylindricalCanine and CuboidalCanine—through code-signing certificates

In part two of this blog series, we're exploring CubodialCanine (Expel-TA-0003), and comparing their attack styles to CylindricalCanine (Expel-TA-0002).

Rapid response | 4 min read
ChainDrop: The Mini Shai Hulud npm worm’s latest wave hits keyv and cacheable

A self-propagating npm worm hit keyv, cacheable, and hundreds of dependent packages to steal CI/CD, cloud, and API credentials. Here's what to do now.

Product | 3 min read
Expel now covers the full AI attack surface

Expel is the top MDR provider covering the full AI attack surface: AI-powered attacks, employee misuse, and exposure inside AI systems. See what's live now.

Product | 3 min read
What we built: July 2026

In July, Expel launched six new threat hunts spanning the AI attack surface, for new features, and one integration update.

Threat intel | 2 min read
Expel’s Q2 2026 threat report: Identity’s back on top, and Teams phishing isn’t slowing down

Expel's Q2 2026 threat data: identity attacks jump to 68.1%, Teams phishing drives an endpoint spike, and a new supply chain worm hits cloud infrastructure.

Expel culture | 4 min read
Meet the Expletive: Josh Carter, SOC Manager

Meet Josh Carter, SOC manager at Expel. He's a self-taught multi-instrumentalist with a firm stance on pizza: triangles only.

Threat intel | 8 min read
When red teams go off the rails, who’s at fault?

Why do red team reports focus on tactics attackers rarely use? Expel's data reveals the misalignment—and a better model.

Threat intel | 6 min read
The feature that stops BYOVD (bring your own vulnerable driver)

BYOVD attacks beat driver blocklists every time. See how WDAC/App Control for Business—deployed via Active Directory—closes the gap for good.

Threat intel | 13 min read
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

CylindricalCanine is a new threat group within GoldenEyeDog, and they're actively using their malware for email phishing. Here's what you need to know.

Threat intel | 2 min read
Patch Tuesday: July 2026 (Expel’s version)

July's Patch Tuesday release includes a record-breaking 570 CVEs. These are the four we think need your attention now.

Rapid response | 2 min read
The “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePuffer

Analysis of agentic ransomware JadePuffer: human operator, LLM agent limits, and why fundamentals still protect defenders.