EXPERT

Charlie Kelly

Charlie Kelly

Expert: Charlie Kelly

Role: Principal Security Analyst

Specialises in: Incident Response

About Charlie Kelly
Charlie is a Principal Security Analyst at Stripe OLT, and former Microsoft and CrowdStrike Security Engineer. He focuses on Incident Response and Defensive Security, as well as mentoring, building side projects and drinking coffee. As a Hack The Box Ambassador and UK Meetup Lead, Charlie fosters community engagement and drives skill development across cyber security, locally and beyond.
  • Has Trust Become Your Biggest Attack Surface? Understand the Key Cyber Trends in 2026.

    he 2026 Cyber Threat Report explores how attackers are exploiting people, identities and trust to bypass traditional defences, helping UK SME leaders understand the risks they need to prioritise in 2026. Following responsible disclosure of our findings, Google removed ModHeader from the Chrome Web Store on 10 July 2026. However, we recommend organisations should still identify and remove existing installations, review historical activity and investigate potential exposure...
    July 17, 2026
  • Hidden Exfiltration Capability Discovered in a Trusted, 900,000-User Chrome Web store Extension 

    Our SOC team recently uncovered hidden surveillance functionality within a trusted browser extension, including capabilities designed to collect browsing activity, generate unique identifiers and communicate with external infrastructure. Following responsible disclosure of our findings, Google removed ModHeader from the Chrome Web Store on 10 July 2026. However, we recommend organisations should still identify and remove existing installations, review historical activity and investigate potential exposure...
    July 17, 2026
  • CYBERUK 2026 – Key Takeaways

    This Expert Intel summarises the key cyber security themes from CYBERUK 2026, exploring how AI is accelerating attacker capability, why identity remains the primary control gap, and what UK based organisations should prioritise to strengthen detection, response, and supply chain resilience.
    July 9, 2026
  • Person using a laptop with the Google search homepage open

    ChatGPT Stealer Explained: The Risk of Malicious Browser Extensions

    AI chat content has become a high-value target for attackers. In this session, we break down a recently identified malicious campaign known as a ChatGPT Stealer, exploring the types of data that can be exposed, the indicators of compromise to watch for, and how to detect and respond to this activity within an enterprise environment.
    July 9, 2026
  • stock-neon

    Analysing Targeted Spearphishing: Social Engineering, Domain Rotation, and Credential Theft

    The Stripe OLT SOC has identified a sophisticated Spearphishing campaign targeting senior employees, particularly those in C-Suite and leadership positions. Actors behind this campaign are leveraging tailored emails that impersonate internal HR communication to trick recipients into entering corporate credentials.
    December 2, 2025
  • Scattered spider

    Unravelling the Web: An Overview of Scattered Spider

    An overview of Scattered Spider, one of today’s most notorious cybercrime groups. Discover who they are, how they operate, and why UK organisations are being increasingly targeted.
    June 18, 2025
  • The Rise of Clickfixing: Understanding the Latest Social Engineering Threat

    Social engineering is evolving, and Clickfixing is the latest threat to watch out for. By exploiting user trust with fake verification prompts, attackers trick victims into executing malicious scripts without realizing it. In this intel, our expert, Charlie, breaks down how Clickfixing works, why it’s so effective, and how to protect your business from this emerging threat. Stay ahead of evolving attacks with practical strategies and insights.
    June 20, 2025
find us on Youtube

Unlock the secrets of cybersecurity, Explore our videos for expert insights and actionable strategies