Security Consultant
Tom Keech
Tom is a penetration tester at Sentrium with strong practical skills and recognised certifications, actively developing expertise through hands-on labs, CTF challenges, and real-world testing. Tom holds CREST CRPT, TCM PNPT, TryHackMe PT1, and INE Security eJPT certifications, and has competed in CTFs for over five years.
Tom is motivated by solving complex problems and sharing knowledge. He focuses on research and engagements that provide practical, actionable insights, combining creative problem solving with the responsibility to protect people and organisations from real-world threats.
Connect with Tom
Areas of expertise
- Web application testing
- API testing
- Infrastructure security
- Cloud security and secure configuration
Writing focus
Tom focuses on practical research and real-world findings from engagements, highlighting common vulnerabilities and their impact. His writing aims to help readers understand how issues can be exploited, why they matter, and how to mitigate them effectively.
Tom's work
-
May 14, 2026
Bleeding Ollama Out-of-Bounds Read Vulnerability (CVE-2026-7482)
Read more arrow_right_alt
-
-
-
January 5, 2026
MongoBleed: unauthenticated memory disclosure in MongoDB (CVE-2025-14847)
Read more arrow_right_alt
-
December 4, 2025
React and Next.js unauthenticated remote code execution (CVE-2025-55182, CVE-2025-66478)
Read more arrow_right_alt
-
November 7, 2025
Cisco Unified CCX Remote Code Execution Vulnerabilities (CVE-2025-20354, CVE-2025-20358)
Read more arrow_right_alt
-
October 30, 2025
Scoping a web application penetration test: What else you need to consider
Read more arrow_right_alt
-
October 27, 2025
Windows Server Update Service (WSUS) remote code execution vulnerability (CVE-2025-59287)
Read more arrow_right_alt
-
April 9, 2024
An introduction to password security: How to crack a password
Read more arrow_right_alt