Expel

@expelsecurity.bsky.social

The leader in agentic MDR. đź”— expel.com

A self-propagating npm supply chain worm compromised keyv, cacheable, flat-cache, file-entry-cache, and 800+ downstream packages—stealing CI/CD, cloud, and API credentials along the way. (1/6)

In April 2026, a Chinese cybercrime group accessed a support rep's device at DigiCert—then used that access to steal code-signing certificates meant for DigiCert customers. We're calling the actors CylindricalCanine. 🧵 1/4

Bild

The Gentlemen ransomware, in a BYOVD attack, used a zero-day exploit to kill EDRs before deploying their payload. The driver they abused wasn't on any public blocklist. Here's our analysis of their techniques. đź§µ

Bild

By now you've probably seen the Mini Shai Hulud supply chain story. TeamPCP compromised 170+ npm and PyPI packages—TanStack, Mistral AI, OpenSearch, and more. Here's what you need to know if you're responding right now. (1/7)

Beware of what you copy and paste. In March 2026, a new watering hole attack called "InstallFix" accounted for 13% of all malware incidents we observed. The lure? Fake install pages for Claude Code. Here is how it works and how to defend your environment. 1/7

Bild

The Axios npm package is a component of many popular applications. Its compromise in turn impacted a lot of systems and software that relied on it. The package was actively serving a remote access trojan to Windows, macOS, and Linux systems. 1/3

Iran's cyber capabilities — ransomware, data wipers, stated intent to target Western infrastructure — aren't theoretical. Expel's James Shank and Iran intel expert Steph Shample give security teams the straight picture: what's real, what it means, and what to do about it. expel.com/resource/ira...

Iran cyber threats: What security teams need to know right now | Expel briefing | Expel

What security teams need to know about Iran cyber threats. Expert insights on Iranian capabilities, TTPs, and defensive measures to implement today.

expel.com

We continue to see high volumes of targeted phishing via Microsoft Teams. The following are malicious senders just from this past week: Corporat[@]HelpDeskFoundation[.]onmicrosoft[.]com service[@]helpdeskfoundation[.]onmicrosoft[.]com helpdesk[@]omkarcis[.]online 1/5

Bild

We just dropped a new AI upgrade 🫳 Now you get plain-English explanations for every detection rule. See exactly which rules are firing, how your coverage evolves, and what's actually protecting you. Transparency isn't a feature, it's how MDR should work. expel.com/blog/new-exp...

New Expel AI upgrade: “Pop the hood” on our detection strategies

Expel added new AI-generated descriptions to our detection rules, written in plain English, to improve transparency and understanding.

expel.com

Your analysts are drowning. You can't hire fast enough. And even if you could, the math doesn't work. The economics of running a 24Ă—7 SOC have changed. Use our free calculator that shows you what your team needs whether that's building, buying, or augmenting: expel.com/blog/buildin...

Why building a 24x7 SOC is getting harder (and what actually works instead)

The math on building an in-house SOC has changed, including the real costs, why retention is brutal, and what actually works.

expel.com

In the SOC, you get used to the noise. But a couple weeks ago, a single string cut through the noise: SHA1HULUD. It felt like seeing a ghost. We traced the activity to a public GitHub repository where the customer's private cloud keys and secrets were exposed for anyone to grab.

Part two of our QTR, Q3 2025 just dropped: malware disguised as apps that actually work. BaoLoader hides backdoors in PDF editors and browsers. TamperedChef is a recipe app with hidden command codes. These apps function as promised, which is why users don't suspect anything.

Q3 2025 Threat Report is out. We analyzed thousands of real incidents across customer environments. Here’s what stood out: 73.9% of all incidents were identity-based attacks. Up from 67.6% last quarter. Let’s dive into the Q3 numbers 🧵

The Rhysida ransomware gang (formerly Vice Society) is running the same playbook as last year—buying Bing ads to deliver fake Microsoft Teams, PuTTy, and Zoom downloads. Click the wrong sponsored result? You’ve just installed OysterLoader, their initial access malware.

⚠️Attackers are actively exploiting CVE-2025-59287, a recently identified vulnerability in WSUS. Successful exploitation allows an attacker to run code using SYSTEM privileges. Expel caught & contained incidents related to this in two customer environments this AM. Details: expel.com/blog/wsus-re...

Bild

Attackers found a clever way to abuse legitimate, digitally signed software to load malware and it's working. Expel Intel’s Marcus Hutchins (@malwaretech.com) breaks down a campaign that weaponizes Greenshot, a legit screenshot tool, to evade detection at multiple layers. 🧵

Halloween might be the spookiest day in October but this month's Patch Tuesday is a close second. 175 new CVEs from Microsoft, 8 marked critical, 6 zero-days, 2 already exploited in the wild. But not to fear, our threat intel team breaks down the 3 you should patch first. expel.com/blog/patch-t...

Patch Tuesday: October 2025 (Expel’s version)

This month, we're highlighting top critical vulnerabilities, including six zero-day vulnerabilities, and one in Cisco IOS.

expel.com

⚠️ Our threat intel team just caught attackers using a clever new trick to bypass security tools: cache smuggling. Instead of downloading malware, they hide it in fake images that browsers automatically cache. Then PowerShell extracts and runs it—no web requests needed.

Bild

The security industry is drowning in threat feeds that don't actually help you stop attacks. We've been working to fix that for years. Today, we’re taking the wraps off our expanded threat intel program: Expel Intel. (1/7)

Your email security quarantined the malicious email. 🚨📧 Victory, right? Not quite so. Several employees already clicked the link and installed attacker-controlled tools.