2025-12-22 – Weekly Cybersecurity News : IoT devices failing security tests

Last week, our community delved into a range of pertinent cybersecurity issues. Discussions were rich with insights into the evolving landscape of threat detection, particularly concerning false positives and their impact on security protocols. The conversation around post-quantum cryptography migration training gained traction, highlighting the urgency for preparedness in this area. Members also shared experiences and strategies for enhancing cloud security and dealing with supply chain compromises, revealing the ongoing challenges and opportunities in these domains.


This Week’s Hot Topics

When the fridge failed the pentest
A surprisingly engaging thread about what happens when IoT devices, like smart fridges, fall short during security tests. It’s a reminder of the complexities in securing everyday devices.
Read more here

We’ll patch later isn’t a mitigation
This topic addresses the common misconception that delaying patches is a viable strategy, emphasizing the importance of timely updates in maintaining security posture.
Read more here

False positive that rewrote my playbook
Explore a firsthand account of how a false positive led to a complete overhaul of security protocols, illustrating the need for precision in threat detection.
Read more here

Best training for PQC migrations this year
This is a must-read for anyone looking to stay ahead in post-quantum cryptography. The discussion revolves around the best training resources available right now.
Read more here

Earliest supply chain compromise you know
Members share historical anecdotes of supply chain breaches, shedding light on how these incidents have evolved and what we can learn from them.
Read more here

My honeypot’s new pickup lines
A lighthearted yet insightful discussion on innovative strategies for deploying honeypots to lure and learn from attackers.
Read more here

Leveling up cloud security this year
This thread is packed with tips and experiences on enhancing cloud security, a critical focus as more organizations migrate to cloud environments.
Read more here

Breaking in through compliance and policy
An intriguing look at how security can be breached through compliance loopholes and policy oversights, emphasizing the need for robust governance.
Read more here

First framework to use the five functions
Discover the origins of the first security framework that utilized the five core functions, with discussions on its impact and relevance today.
Read more here


Thanks for staying engaged with our community. Your contributions and insights help us all navigate the complex world of cybersecurity more effectively. Until next time, take care and stay secure.

Treat IoT like noisy roommates — give them their own VLAN “room” and build a per‑firmware “known‑good” baseline; we cut false positives by about 40% last quarter, and only alerts that deviate from both fire while the rest auto‑expire after 14 days unless reviewed. Small caveat: don’t blanket‑suppress — tie every suppression to an owner and an expiry. For PQC prep, we tagged crypto libraries in our SBOM to see which gateways can handle hybrid KEMs; NISTIR 8259 helped prioritize controls: IR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers | CSRC.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌‍​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠​‍​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‍​‌⁠​‌‌​‌‌‌⁠‌‌‌⁠‌‌​⁠‍​‌‍⁠‍‌‌​⁠‌‍‌​‌‌​​‌‌​​‌​‌‌‌​​⁠‌​‍⁠‌‍⁠⁠​⁠​‌​‍​‍‌⁠⁠‌​

@sreed32 Quick win for us: enable RFC 8520 MUD (RFC 8520 - Manufacturer Usage Description Specification) on the access layer so new IoT joining via 802.1X/MAB pull a MUD URL and we auto‑build per‑model egress allowlists. It cut false positives and made failing tests obvious; caveat, some vendors ship bad MUD files so we override a few by hand.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠​⁠​⁠‌‍​⁠​‌​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‍​⁠​‍​⁠‌​​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‍‌⁠​‍​⁠‌‌‌‌​⁠‌‍‌‌‌‌​‌‌‍‍​​⁠‍​‌​‍​‌​‍⁠‌‍‌​‌‍‍⁠‌‍‌⁠‌‍​‌‌‌‌‌‌‍‍⁠​‍​‍‌⁠⁠‌​