AI malware: The claims are getting wilder, but the reality is more interesting 2026-05-21 True True Patch Tuesday: May 2026 (Expel’s version) 2026-05-12 True True Mini Shai Hulud: Cross-ecosystem supply chain worm targeting npm & PyPI 2026-05-12 True True The AI threat that’s actually worth worrying about from Q1 2026 (part two) 2026-05-01 True True How AI is reshaping the threat landscape, and what our Q1 2026 data shows (part one) 2026-04-30 True True cPanel released a patch for a WebHost Manager (WHM) authentication bypass bug 2026-04-29 True True More supply chain compromises: Namaste, xinference, and more 2026-04-22 True True Inside Lazarus: How North Korea uses AI to industrialize attacks on developers 2026-04-22 True True OAuth hijacked: How a third-party breach hit Vercel 2026-04-20 True True Revisiting sound guidance: Countering the heightened threat of device code phishing 2026-04-17 True True InstallFix: Not the application you were looking for 2026-04-15 True True Patch Tuesday: April 2026 (Expel’s version) 2026-04-14 True True Why identity security is a verb, not a noun 2026-04-08 True True Security alert: Axios npm supply chain attack 2026-03-31 True True On the radar: ChatGPT Stealer 2026-03-24 True True Patch Tuesday: March 2026 (Expel’s version) 2026-03-10 True True What security teams need to know about Iran’s cyber threat right now 2026-03-06 True True Patch Tuesday: February 2026 (Expel’s version) 2026-02-11 True Ben Nahorney; Matt Jastram True Notepad++ supply chain incident 2026-02-02 True Aaron Walton True Security alert: Critical unauthenticated RCE vulnerabilities in Ivanti EPMM 2026-01-30 True Aaron Walton True ClearFake gets more evasive with new living off the land (LOTL) techniques 2026-01-20 True Marcus Hutchins True Planned failure: Gootloader’s malformed ZIP actually works perfectly 2026-01-15 True Aaron Walton True Patch Tuesday: January 2026 (Expel’s version) 2026-01-14 True Matt Jastram; Ben Nahorney True On the radar: Weeding out XMRig 2026-01-07 True Ben Nahorney True Stories from the SOC: The second coming of Shai Hulud 2025-12-23 True Isa Judd; Ben Nahorney True Patch Tuesday: December 2025 (Expel’s version) 2025-12-10 True Ben Nahorney; Matt Jastram True Active exploitation notice: React2Shell critical vulnerability (CVE-2025-55182) 2025-12-09 True Aaron Walton; Matt Jastram True Stories from the SOC: Mystery of the postponed proxyware install 2025-11-24 True Ben Nahorney; Sean Scully True Patch Tuesday: November 2025 (Expel’s version) 2025-11-12 True Ben Nahorney; Matt Jastram True Expel Quarterly Threat Report, Q3 2025: Threat intel recap 2025-11-06 True Ben Nahorney; Aaron Walton True Expel Quarterly Threat Report, Q3 2025: Q3 by the numbers 2025-11-05 True Ben Nahorney; Aaron Walton True Certified OysterLoader: Tracking Rhysida ransomware gang activity via code-signing certificates 2025-10-31 True Aaron Walton True Stories from the SOC: The curious case of termination notices 2025-10-29 True Ben Nahorney; Isa Judd; Hafsah Mijinyawa True Security alert: WSUS remote code execution vulnerability 2025-10-24 True Aaron Walton True Along for the ride: When legitimate software becomes a signed malware loader 2025-10-23 True Marcus Hutchins True Patch Tuesday: October 2025 (Expel’s version) 2025-10-15 True Ben Nahorney; Matt Jastram True Cache smuggling: When a picture isn’t a thousand words 2025-10-08 True Marcus Hutchins True Stories from the SOC: When threats come from inside the house 2025-09-29 True Ben Nahorney; Zach Davis True Gonzo threat hunting: LapDogs & ShortLeash 2025-09-24 True Malachi Woodlee True The history of AppSuite: the certs of the BaoLoader developer 2025-09-11 True Aaron Walton True Patch Tuesday: September 2025 (Expel’s version) 2025-09-09 True Ben Nahorney; Matt Jastram True You don’t find ManualFinder, ManualFinder finds you 2025-08-22 True Aaron Walton True Patch Tuesday: August 2025 (Expel’s version) 2025-08-13 True Ben Nahorney; Matt Jastram; Aaron Walton True An important update (and apology) on our PoisonSeed blog 2025-07-25 True True Explore Expel’s auto remediations: Disable access key 2025-07-25 True Jake Godgart True Expel Quarterly Threat Report, Q2 2025: Threat intel recap 2025-07-24 True Ben Nahorney; Aaron Walton True Update on the SharePoint ToolShell vulnerability exploitation (CVE-2025-53770) 2025-07-22 True Matt Jastram; Brandon Overstreet; Ben Nahorney; Aaron Walton True Expel Quarterly Threat Report, Q2 2025: Q2 by the numbers 2025-07-22 True Aaron Walton; Ben Nahorney True Patch Tuesday: July 2025 (Expel’s version) 2025-07-08 True Aaron Walton; Ben Nahorney; Matt Jastram True Security alert: Citrix NetScaler ADC and NetScaler Gateway vulnerabilities allow unauthorized access 2025-06-28 True Aaron Walton True