Threat intel
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.

Product | 3 min read
What we built: July 2026

In July, Expel launched six new threat hunts spanning the AI attack surface, for new features, and one integration update.

Threat intel | 2 min read
Expel’s Q2 2026 threat report: Identity’s back on top, and Teams phishing isn’t slowing down

Expel's Q2 2026 threat data: identity attacks jump to 68.1%, Teams phishing drives an endpoint spike, and a new supply chain worm hits cloud infrastructure.

Expel culture | 4 min read
Meet the Expletive: Josh Carter, SOC Manager

Meet Josh Carter, SOC manager at Expel. He's a self-taught multi-instrumentalist with a firm stance on pizza: triangles only.

Threat intel | 8 min read
When red teams go off the rails, who’s at fault?

Why do red team reports focus on tactics attackers rarely use? Expel's data reveals the misalignment—and a better model.

Threat intel | 6 min read
The feature that stops BYOVD (bring your own vulnerable driver)

BYOVD attacks beat driver blocklists every time. See how WDAC/App Control for Business—deployed via Active Directory—closes the gap for good.

Threat intel | 13 min read
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident

CylindricalCanine is a new threat group within GoldenEyeDog, and they're actively using their malware for email phishing. Here's what you need to know.

Threat intel | 2 min read
Patch Tuesday: July 2026 (Expel’s version)

July's Patch Tuesday release includes a record-breaking 570 CVEs. These are the four we think need your attention now.

Rapid response | 2 min read
The “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePuffer

Analysis of agentic ransomware JadePuffer: human operator, LLM agent limits, and why fundamentals still protect defenders.

Product | 2 min read
What we built: June 2026

See what Expel shipped in June 2026, including two new threat hunts and updated CrowdStrike Falcon detection coverage.

Threat intel | 19 min read
Not very gentlemanly: Analyzing a zero-day exploit used by The Gentlemen ransomware to disable targets’ EDRs

How the threat group used a zero-day vulnerability to disable the target's EDR, preventing it from intervening in their ransomware attack.

MDR | 5 min read
How one payments network does it all: Scaling without headcount, and keeping humans in the loop

Affirm's security team covers dozens of AWS accounts. Here's how their MDR keeps pace with human-in-the-loop judgment as they scale—without adding headcount.

Product | 5 min read
Ruxie AI now covers every stage of the threat lifecycle

Expel extends Ruxie with new agentic AI capabilities across every stage of the threat lifecycle—from enrichment and detection to response and reporting.