CISSP
Certified Information Systems Security Professional
ISC2Penetration Tester · Security Researcher
I'm Abdullah Kareem. 47 assigned CVEs in software such as vLLM, Jackson Databind and Parse Server, backed by CISSP, OSWE, OSEP and OSCP.
Recent research
Vulnerabilities found and reported in real-world software, like:
vLLM · Jackson Databind · Parse Server · OpenProject · Grav · Infracost · Uyuni · Bazarr · Frigate
See the full ledgerExperience
My background spans infrastructure operations, security engineering, and authorized penetration testing.
See selected workEjabi InfoSec
Authorized application, mobile, and adversary-simulation assessments with peer review and remediation-focused reporting.
Smart Oasis Company
Network and identity testing, vulnerability management, monitoring, and security-by-design review.
United Nations
Enterprise infrastructure, identity modernization, network operations, security response, and staff awareness.
About
I'm Abdullah Kareem, known as CyberKareem. I test applications, APIs, mobile systems, infrastructure, identity, and defined cloud environments. My engineering and operations background helps me explain both the attack path and a practical fix. The part I care about most is the handoff: a finding a team can reproduce and a fix they can ship.
Web, API, and mobile-backed systems, with emphasis on access control, business logic, source-to-sink review, and reproducible remediation evidence.
Attack-path reasoning across identity, internal networks, and applications.
Enterprise infrastructure, identity, networks, segmentation, and scoped AWS, Azure, or Google Cloud review where the system and evidence access fit.
Local-first analysis, assessment automation, evidence packaging, and vulnerability-research workflows with explicit operating limits.
Education
University of East London
Sep 2025 to Dec 2026University of the People
Apr 2024 to Aug 2025University of Anbar
2011 to 2015Credentials
Provider-issued records are linked directly. Current, earlier, and specialist-training records are separated below.
Certified Information Systems Security Professional
ISC2OffSec Web Expert
OffSecOffSec Experienced Penetration Tester
OffSecOffSec Certified Professional
OffSecMobile Application Penetration Tester
INE SecurityProject Management Professional
Project Management InstituteAssessed Solidity, EVM, and DeFi security training supports bounded readiness reviews. It is not presented as production protocol-audit history.
12 current or non-expiring professional certification records.
HTB Certified Web Exploitation Expert
Hack The BoxHTB Certified Active Directory Pentesting Expert
Hack The BoxOffSec Web Expert
OffSecOffSec Experienced Penetration Tester
OffSecOffSec Certified Professional+
OffSecOffSec Certified Professional
OffSecMobile Application Penetration Tester
INE SecurityHack The Box Certified Penetration Testing Specialist
Hack The BoxCertified Information Systems Security Professional
ISC2Project Management Professional
Project Management InstituteOffSec Wireless Professional
OffSecCertified Professional Penetration Tester
INE SecurityProvider-verified final assessment and hands-on labs supporting bounded Solidity/EVM readiness reviews. This is not presented as production protocol-audit history.
Smart Contract Hacking (Solidity/EVM)
Blockchain Security AcademyCompleted both parts of JohnnyTime's assessed curriculum: 33 hours and 50 hands-on exercises across Solidity/EVM security, exploit proof-of-concept development, and DeFi attack paths.
Credential ID4cabe4baa46be2df98f2b9d3bc644debc4902bef198193d054cef23b3b7ddad5
9 expired records retained as dated professional history, not presented as current qualifications.
Certified Ethical Hacker
EC-CouncilCisco Certified Network Professional Enterprise
CiscoCisco Certified Network Professional Routing and Switching
CiscoCisco Certified Specialist - Enterprise Advanced Infrastructure
CiscoCisco Certified Specialist - Enterprise Core
CiscoCisco Certified Network Associate
CiscoCisco Certified Network Associate Routing and Switching
CiscoITIL 4® Foundation
PeopleCertITIL® Foundation
PeopleCertCurrent certifications, assessed training, and earlier records are shown separately so their status is clear. Some providers issue companion or successor designations, so the total counts public credential records rather than unique examinations.
Public verification
Issuer records and public researcher profiles.
Selected evidence
Public source, methodology, and operating limits accompany each entry.
An LLM-assisted variant-analysis engine that validates and ranks static-analysis matches into a short list of manually-verifiable leads.
Python · Public MVPView project Recon intelligenceA local-first attack-surface workbench for turning common recon output into explainable priorities.
Python · Public MVPView project Security engineeringseg-test runs approved checks from defined source VLANs, preserves raw Nmap output, and packages evidence without making compliance decisions.
12 Jul 2026 · 10 minRead article Security engineeringA reviewed account of a BitLocker-based cryptographic-erase prototype, its operating assumptions, and the validation required before real-world use.
19 May 2025 · 6 minRead articleWriting
Notes on security research, tooling, and the work behind the findings.
Start a conversation
Email me directly. For assessment or disclosure enquiries, start with high-level context and move sensitive details to an agreed private channel.