
(replay) Common Pentest Findings That Shouldn't Exist in 2025
About this episode
In this episode of The Cyber Threat Perspective, we highlight the pentest findings that, frankly, have no business showing up in 2025. From accounts with weak passwords and no MFA to plaintext credentials on file shares, we break down the common misconfigurations and oversights that attackers still abuse, despite years of seeing the same issues over and over again. If you're an IT admin or security leader, this episode is your checklist of what to fix yesterday.
Blog: https://offsec.blog/
Youtube: https://www.youtube.com/@cyberthreatpov
Twitter: https://x.com/cyberthreatpov
Follow Spencer on social ⬇
Spencer's Links: https://spenceralessi.com
Work with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Get every episode summarized
Each time The Cyber Threat Perspective publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Cyber Threat Perspective

Episode 173: How to Find Insecure Active Directory Permissions with ADeleg
The Cyber Threat Perspective

Episode 172: The biggest security blind spots in Midsized companies
The Cyber Threat Perspective

Episode 171: The future of pentesting with AI
The Cyber Threat Perspective

Episode 170: The Evasive Adversary
The Cyber Threat Perspective