Expel @expelsecurity.bsky.social · 20/08/2026On August 18, we caught a malware loader we believe to be novel. Entry point: a threat actor phished a client’s user through Microsoft Teams, posing as the IT help desk. We named it SynkLoader. (1/7) 100
Expel @expelsecurity.bsky.social · 04/08/2026A self-propagating npm supply chain worm compromised keyv, cacheable, flat-cache, file-entry-cache, and 800+ downstream packages—stealing CI/CD, cloud, and API credentials along the way. (1/6) 100
Expel @expelsecurity.bsky.social · 15/07/2026In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4 110
Expel @expelsecurity.bsky.social · 06/07/2026Researchers at Sysdig found JadePuffer used an LLM agent to conduct a ransomware attack. Is this future of ransomware? In this case, a human still steered it and struggled with the basics. expel.com/blog/the-fir...expel.comThe “first” fully agentic ransomware is here, but we aren’t panicking (yet): Meet JadePufferAnalysis of agentic ransomware JadePuffer: human operator, LLM agent limits, and why fundamentals still protect defenders. 000
Expel @expelsecurity.bsky.social · 02/07/2026The Gentlemen ransomware, in a BYOVD attack, used a zero-day exploit to kill EDRs before deploying their payload. The driver they abused wasn't on any public blocklist. Here's our analysis of their techniques. 🧵 210
Expel @expelsecurity.bsky.social · 13/05/2026Need a high-level overview of the latest Mini Shai Hulud? Aaron Walton breaks down how the latest supply chain attack happened, what defenders should do now, and prepare for the next one. www.youtube.com/shorts/7x9t6...youtube.comMini Shai-Hulud: the wormable attack targeting your supply chainYouTube video by Expel 010
Expel @expelsecurity.bsky.social · 12/05/2026By now you've probably seen the Mini Shai Hulud supply chain story. TeamPCP compromised 170+ npm and PyPI packages—TanStack, Mistral AI, OpenSearch, and more. Here's what you need to know if you're responding right now. (1/7) 100
Expel @expelsecurity.bsky.social · 15/04/2026Beware of what you copy and paste. In March 2026, a new watering hole attack called "InstallFix" accounted for 13% of all malware incidents we observed. The lure? Fake install pages for Claude Code. Here is how it works and how to defend your environment. 1/7 110
Expel @expelsecurity.bsky.social · 31/03/2026The Axios npm package is a component of many popular applications. Its compromise in turn impacted a lot of systems and software that relied on it. The package was actively serving a remote access trojan to Windows, macOS, and Linux systems. 1/3 120
Expel @expelsecurity.bsky.social · 06/03/2026Iran's cyber capabilities — ransomware, data wipers, stated intent to target Western infrastructure — aren't theoretical. Expel's James Shank and Iran intel expert Steph Shample give security teams the straight picture: what's real, what it means, and what to do about it. expel.com/resource/ira...expel.comIran cyber threats: What security teams need to know right now | Expel briefing | ExpelWhat security teams need to know about Iran cyber threats. Expert insights on Iranian capabilities, TTPs, and defensive measures to implement today. 010
Expel @expelsecurity.bsky.social · 04/03/2026We continue to see high volumes of targeted phishing via Microsoft Teams. The following are malicious senders just from this past week: Corporat[@]HelpDeskFoundation[.]onmicrosoft[.]com service[@]helpdeskfoundation[.]onmicrosoft[.]com helpdesk[@]omkarcis[.]online 1/5 100
Expel @expelsecurity.bsky.social · 14/01/2026Security and finance leaders think they're aligned. Our new research with 300 of them says otherwise. 54% of finance leaders need strategic alignment metrics. Security's giving them maturity metrics instead. The language barrier is real—and fixable. expel.com/blog/new-res... 000
Expel @expelsecurity.bsky.social · 09/01/2026We just dropped a new AI upgrade 🫳 Now you get plain-English explanations for every detection rule. See exactly which rules are firing, how your coverage evolves, and what's actually protecting you. Transparency isn't a feature, it's how MDR should work. expel.com/blog/new-exp...expel.comNew Expel AI upgrade: “Pop the hood” on our detection strategiesExpel added new AI-generated descriptions to our detection rules, written in plain English, to improve transparency and understanding. 010
Expel @expelsecurity.bsky.social · 07/01/2026We're seeing XMRig cryptominers popping up everywhere recently. Threat actors love them because they’re a simple way to make money, and they can go unnoticed. Here's how to spot them and shut them down before threat actors start monetizing: expel.com/blog/on-the-...expel.comOn the radar: Weeding out XMRigXMRig is a cryptocurrency miner considered less malicious than other threats, but it's still worth prioritizing. 000
Expel @expelsecurity.bsky.social · 02/01/2026Our security leaders made their (brutally honest) 2026 predictions. The one thing they agree on? AI isn’t going anywhere, and it’s bringing new capabilities and threats into the new year. Read all of their unfiltered takes: expel.com/blog/cyberse...expel.comOur cybersecurity predictions for 2026Our experts and leaders are sharing their predictions for cybersecurity trends in 2026 to help you start strategizing. 000
Expel @expelsecurity.bsky.social · 29/12/2025Your analysts are drowning. You can't hire fast enough. And even if you could, the math doesn't work. The economics of running a 24×7 SOC have changed. Use our free calculator that shows you what your team needs whether that's building, buying, or augmenting: expel.com/blog/buildin...expel.comWhy building a 24x7 SOC is getting harder (and what actually works instead)The math on building an in-house SOC has changed, including the real costs, why retention is brutal, and what actually works. 000
Expel @expelsecurity.bsky.social · 23/12/2025In the SOC, you get used to the noise. But a couple weeks ago, a single string cut through the noise: SHA1HULUD. It felt like seeing a ghost. We traced the activity to a public GitHub repository where the customer's private cloud keys and secrets were exposed for anyone to grab. 120
Expel @expelsecurity.bsky.social · 16/12/2025Expel MDR now supports Panther. We integrate with your cloud-native SIEM, bringing our detections, 24x7 monitoring, and incident response to work alongside what you've already built. Use the tools that work for you. We'll make them work harder. expel.com/blog/more-si...expel.comMore SIEM flexibility: Expel MDR adds support for PantherExpel announces support for Panther's cloud-native SIEM as the latest in our long list of advanced integrations. 000
Expel @expelsecurity.bsky.social · 09/12/2025⚠️ Attackers are buying Google Ads that appear when looking up how to troubleshoot your Mac. The ad takes you to a shared ChatGPT chat that tells you to copy-paste some code. You've just executed malware. Kroll has a solid write-up on the mechanics: www.kroll.com/en/publicati... 000
Expel @expelsecurity.bsky.social · 06/11/2025Part two of our QTR, Q3 2025 just dropped: malware disguised as apps that actually work. BaoLoader hides backdoors in PDF editors and browsers. TamperedChef is a recipe app with hidden command codes. These apps function as promised, which is why users don't suspect anything. 100
Expel @expelsecurity.bsky.social · 05/11/2025Imagine searching for Microsoft Teams, visiting the link at the top of the results, & getting hit with malware. That's the malvertising campaign that the Rhysida ransomware gang has been running. Expel Intel is tracking this campaign. Here's what we've uncovered: www.theregister.com/2025/10/31/r...theregister.comRansomware gang runs ads for Microsoft Teams to pwn victims: You click and think you're getting a download page, but get malware instead 000
Expel @expelsecurity.bsky.social · 05/11/2025Q3 2025 Threat Report is out. We analyzed thousands of real incidents across customer environments. Here’s what stood out: 73.9% of all incidents were identity-based attacks. Up from 67.6% last quarter. Let’s dive into the Q3 numbers 🧵 100
Expel @expelsecurity.bsky.social · 31/10/2025The Rhysida ransomware gang (formerly Vice Society) is running the same playbook as last year—buying Bing ads to deliver fake Microsoft Teams, PuTTy, and Zoom downloads. Click the wrong sponsored result? You’ve just installed OysterLoader, their initial access malware. 100
Expel @expelsecurity.bsky.social · 24/10/2025⚠️Attackers are actively exploiting CVE-2025-59287, a recently identified vulnerability in WSUS. Successful exploitation allows an attacker to run code using SYSTEM privileges. Expel caught & contained incidents related to this in two customer environments this AM. Details: expel.com/blog/wsus-re... 010
Expel @expelsecurity.bsky.social · 23/10/2025Attackers found a clever way to abuse legitimate, digitally signed software to load malware and it's working. Expel Intel’s Marcus Hutchins (@malwaretech.com) breaks down a campaign that weaponizes Greenshot, a legit screenshot tool, to evade detection at multiple layers. 🧵 1287
Expel @expelsecurity.bsky.social · 15/10/2025Halloween might be the spookiest day in October but this month's Patch Tuesday is a close second. 175 new CVEs from Microsoft, 8 marked critical, 6 zero-days, 2 already exploited in the wild. But not to fear, our threat intel team breaks down the 3 you should patch first. expel.com/blog/patch-t...expel.comPatch Tuesday: October 2025 (Expel’s version)This month, we're highlighting top critical vulnerabilities, including six zero-day vulnerabilities, and one in Cisco IOS. 010
Expel @expelsecurity.bsky.social · 08/10/2025⚠️ Our threat intel team just caught attackers using a clever new trick to bypass security tools: cache smuggling. Instead of downloading malware, they hide it in fake images that browsers automatically cache. Then PowerShell extracts and runs it—no web requests needed. 100
Expel @expelsecurity.bsky.social · 08/10/2025The security industry is drowning in threat feeds that don't actually help you stop attacks. We've been working to fix that for years. Today, we’re taking the wraps off our expanded threat intel program: Expel Intel. (1/7) 110
Expel @expelsecurity.bsky.social · 02/10/202550k events/day. 0.1% true positive rate. 50 real threats buried. That's what happens when you optimize for integration count, not detection quality. Vendors brag about "300+ integrations" while analysts burn out investigating false positives. Start counting what matters: expel.com/blog/stop-co... 000
Expel @expelsecurity.bsky.social · 29/09/2025Your email security quarantined the malicious email. 🚨📧 Victory, right? Not quite so. Several employees already clicked the link and installed attacker-controlled tools. 100
Expel @expelsecurity.bsky.social · 25/09/2025Chinese threat actors were building a network of SOHO routers and marking their territory with TLS certs that spoofed the LAPD. Our threat hunters found them anyway. 🕵️ 100
Expel @expelsecurity.bsky.social · 23/08/2025⚠️ We’ve recently witnessed new activity in the realm of potentially unwanted programs (PUPs), which are dropping malware, executing commands, and turning your machine into someone else's proxy network. Read our ongoing investigation here: expel.com/blog/you-don...expel.comYou don’t find ManualFinder, ManualFinder finds youWe're investigating ManualFinder, a trojan malware we're seeing in new activity, likely coming from potentially unwanted programs (PUPs). 000
Expel @expelsecurity.bsky.social · 21/08/2025🚨 A NEW trojan on the block spotted by our threat intel team 👀 We saw files with the code-signing signature “GLINT SOFTWARE SDN. BHD.” due to a JavaScript dropping “ManualFinder” One of their signed files, a PDF editor, turns your device into a residential proxy—ew. 🧵👇 100
Expel @expelsecurity.bsky.social · 01/08/2025⚠️ We’ve noticed a campaign leveraging SEO poisoning to drop a small loader. If you’ve seen the lure in the watering hole, we’d love to know. A copy of the malware can be found on VirusTotal as MD5 hash 6af56c606b4ece68b4d38752e7501457. Here’s what we’re seeing 🧵 100
Reposted by ExpelHelp Net Security @helpnetsecurity.com · 17/07/2025What Fortune 100s are getting wrong about cybersecurity hiring 📖 Read more: www.helpnetsecurity.com/2025/07/17/c... #cybersecurity #cybersecuritynews #burnout #certification @expelsecurity.bsky.socialhelpnetsecurity.comWhat Fortune 100s are getting wrong about cybersecurity hiring - Help Net SecurityNew research reveals cybersecurity hiring trends for 2025, showing how rigid job requirements and low flexibility are driving talent away. 021
Expel @expelsecurity.bsky.social · 30/06/2025Spotted in NYC ❎👀 Took cloud security so seriously we actually ended up in the clouds. ☁️ Thanks for having us, Nasdaq! 000
Expel @expelsecurity.bsky.social · 26/06/2025⚠️ We’ve been keeping a close eye on the US-Israel-Iran geopolitical situation. Many resources are providing a ton of information and data but not a lot of analysis. Our take: things are not likely to intensify in the cyber realm. Here's what to do and what Expel is doing:expel.comWhat we're seeing from Iran (and what it means for you)Here's Expel's take on what the geopolitical issues between the US, Israel, and Iran look like for the cybersecurity community to date. 010
Expel @expelsecurity.bsky.social · 23/06/2025📂💥 When a malicious file hits your environment, every second counts. Expel's “delete malicious file” response action enables our SOC to permanently remove a confirmed malicious file directly from an affected host, using the EDRs and security tools you already have. expel.com/blog/explore...expel.comExplore Expel’s auto remediations: Delete malicious fileIn this series, we explore Expel's auto remediations so you understand how they work. Let's explore delete malicious file. 000
Expel @expelsecurity.bsky.social · 20/06/2025⚠️🕷️ Scattered Spider is acting with a heightened amount of activity. We're seeing them pivot from credential harvesting to directly targeting IT help desks, using social engineering to reset passwords and bypass MFA. Get the full 411 on Scattered Spider's heightened activity:expel.comEmerging threat: Scattered Spider’s heightened activity—here’s the 411Threat group Scattered Spider is making headlines again as they increase targeting for financial services and insurance orgs. 000
Expel @expelsecurity.bsky.social · 10/06/2025It’s Patch Tuesday! 🩹 This month, Microsoft released 66 CVEs including CVE-2025-33053 and CVE-2025-33070. Of the vulnerabilities, here are the three that caught our eye as the highest priority due to the vulnerability exploitation risk factors 👀🚨 expel.com/blog/patch-t...expel.comPatch Tuesday: June 2025 (Expel's version)The June 2025 edition of Patch Tuesday is live, and this month we're highlighting a handful of Ivanti critical vulnerabilities. 000
Expel @expelsecurity.bsky.social · 10/06/2025You’ve invested in your SIEM, now our goal is to make that investment 𝘸𝘰𝘳𝘬. We’re doubling down on our position as a leader in MDR flexibility by announcing the expansion of our SIEM coverage. We’ve launched advanced support for Palo Alto Networks Cortex XSIAM this month. 👏 100
Expel @expelsecurity.bsky.social · 09/06/2025Acquisitions happen. But when your security vendor gets bought out, it's not just business as usual. Are you ready to ask the hard questions? Because you need to. Our CSO Greg Notch lays out the 5 questions you need to ask when your security vendor gets acquired: expel.com/blog/5-quest...expel.com5 questions to ask when your security vendor gets acquiredWhether your MDR provider is going through a merger or acquisition, here are five questions you'll want to ask your new point of contact. 000
Expel @expelsecurity.bsky.social · 06/06/2025In 7 minutes you can... 🏃 run a darn good mile 🤳 doom scroll before your next meeting 🖥️ or onboard Expel That's right. The onboarding even includes time to validate the connection within Expel Workbench™ and to test the connection. Watch the full demo and follow along! expel.com/blog/how-to-...expel.comHow to onboard with Expel in 7 minutes (No, really. We'll show you.)See with your own eyes how Expel MDR is up and running in less than seven minutes, from API connection to immeidate protection. 000
Expel @expelsecurity.bsky.social · 03/06/2025🎭 Identity is your new perimeter in cybersecurity. Today, hackers aren’t just breaking in, they’re logging in. In financial services, trust is everything. Your customers and employees need to securely access your services from anywhere. 100
Expel @expelsecurity.bsky.social · 28/05/2025Expel's contain host auto remediation allows our SOC analysts—with your pre-approval—to automatically isolate a compromised or suspicious endpoint from your network. Learn: ⚙️how our contain host auto remediation works 👟how our analysts kick off this action 🖥️how to set it upexpel.comExplore Expel’s auto remediations: Contain hostIn this series, we explore Expel's auto remediations so you understand how they work, and the benefits of each. Let's explore contain host. 000
Expel @expelsecurity.bsky.social · 27/05/2025In media (and cloud) we trust 🫡 Join Pierre Noel on 3rd June at #Infosec2025 for insights on overcoming common cloud transformation challenges in a changing digital media ecosystem. And don't forget to come see us at stand C85 for custom AI portraits and swag. expel.com/infosecurity... 000
Expel @expelsecurity.bsky.social · 23/05/2025🕷️Operation Endgame just announced disruption of the infrastructure behind Lactrodectus malware, a malware used by ransomware actors to gain access to enterprise networks. But the devs are persistent so we expect them to return. Here are the most recent tactics we've seen: expel.com/blog/followi... 000
Expel @expelsecurity.bsky.social · 19/05/2025Mergers and acquisitions can fuel growth but they also create opportunities for cyber threats. Join Expel's experts along with Visa's Ilaiy Elangovan on June 5 for a discussion on expanding your org—without slowing down the deal. 🏦🛡️ Register now: expel.com/webinars/ma-...expel.comHow to protect M&A in FinServ with Visa and Expel | Expel 000
Expel @expelsecurity.bsky.social · 15/05/2025New blog series alert! 🔦 Follow along as we explore all of Expel’s auto remediations. In this post, we'll focus on the kill process auto remediation, which enables Expel's SOC to immediately terminate malicious processes across endpoints. Here's how it works and how to set it up:expel.comExplore Expel’s auto remediations: Kill processIn this series, we explore Expel's auto remediations so you understand how they work, and the benefits of each. Let's explore kill process. 010