Tom Keech

Security Consultant

Tom Keech

Tom is a penetration tester at Sentrium with strong practical skills and recognised certifications, actively developing expertise through hands-on labs, CTF challenges, and real-world testing. Tom holds CREST CRPT, TCM PNPT, TryHackMe PT1, and INE Security eJPT certifications, and has competed in CTFs for over five years.

Tom is motivated by solving complex problems and sharing knowledge. He focuses on research and engagements that provide practical, actionable insights, combining creative problem solving with the responsibility to protect people and organisations from real-world threats.

Connect with Tom

Areas of expertise

  • Web application testing
  • API testing
  • Infrastructure security
  • Cloud security and secure configuration

Writing focus

Tom focuses on practical research and real-world findings from engagements, highlighting common vulnerabilities and their impact. His writing aims to help readers understand how issues can be exploited, why they matter, and how to mitigate them effectively.

Tom's work

  1. CVE-2026-7482 Bleeding Ollama Information Disclosure
  2. Axios 1.14.1 and 0.30.4 Supply Chain Attack

    March 31, 2026

    Axios NPM Supply Chain Compromise

    Read more arrow_right_alt

  3. XWiki CSS injection disclosure

    February 19, 2026

    Disclosure: XWiki CSS Injection (CVE-2026-26000)

    Read more arrow_right_alt

  4. MongoBleed: Unauthenticated memory disclosure vulnerability
  5. React and Next.JS critical RCE
  6. Cisco Unified CCX Remote Code Execution vulnerabilities reported
  7. Password cracking: How to crack a password