2026-01-19 – Weekly Cybersecurity News : 802.1X vs the coffee machine

Last week, our forum saw a diverse range of discussions reflecting the current challenges and innovations in cybersecurity. Members shared practical experiences on how simple, routine fixes can prevent significant breaches, emphasizing the importance of consistent security hygiene. There was also a forward-looking conversation about preparing for AI-driven threats expected in 2026, highlighting the need for evolving training programs. Additionally, aligning Continuing Professional Education (CPE) courses with updated frameworks like NIST CSF 2.0 and CMMC was a hot topic, showcasing the need for continuous learning in our field.


This Week’s Hot Topics

Mundane fixes that avert big breaches
This thread discusses how routine, often overlooked security measures can play a crucial role in averting major breaches. It’s a reminder of the power of the basics.
Read more here

Best training for AI-driven threats in 2026
Explore what the community thinks about the future of cybersecurity training, particularly as AI becomes a more prominent threat.
Read more here

Aligning CPEs with NIST CSF 2.0 and CMMC
Members are discussing how to align professional education with new cybersecurity frameworks, which is crucial for staying relevant.
Read more here

Audit-ready control mapping resources
A valuable exchange of resources for those looking to streamline their audit preparations with effective control mapping strategies.
Read more here

Anyone running PQC-hybrid TLS yet
This conversation delves into the early adoption of post-quantum cryptography solutions, particularly in TLS environments.
Read more here

First 15 minutes of an incident
Learn what actions seasoned professionals prioritize in the crucial first minutes of a cybersecurity incident.
Read more here

802.1X vs the coffee machine
A light-hearted but insightful look into applying network access control in unconventional scenarios, like a coffee machine.
Read more here

Beyond CVSS: practical vuln triage
Discusses how to move beyond just CVSS scores for a more practical approach to vulnerability management.
Read more here

Start with alert triage and a playbook
An engaging thread on setting up effective alert management systems and playbooks, crucial for any security operations center.
Read more here

eBPF sensors for real-world threat hunting
Explore how eBPF sensors are being used in advanced threat hunting and what this means for real-world applications.
Read more here


That’s all for this week’s digest. Stay informed and keep the discussions going. See you next time!

1 Like

But we ran into the β€œ802.1X vs the coffee machine” last week β€” MAC auth bypass to a locked‑down IoT VLAN solved it, and a 30‑day stale‑MAC purge keeps the list from rotting… If you can’t do dynamic VLANs, DHCP fingerprint + egress ACLs works, but , maintenance. Anyone have a cleaner approach that still plays nice with facilities?

β€Œβ β€β β€‹β€β€‹β€β€Œβ β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ€β€‹β β€Œβ β€β€Œβ€Œβ€β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€β€Œβ β€‹β β€Œβ€β€Œβ€Œβ€Œβ€β€‹β β€Œβ β€Œβ€Œβ€Œβ β€‹β€β€Œβ€β€β€Œβ€Œβ β€Œβ€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€‹β€Œβ€β β€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€Œβ€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β β€Œβ€‹β€‹β β€‹β€‹β€‹β β€‹β€‹β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€‹β β€‹β€β€‹β β€‹β€‹β€‹β β€‹β€β€‹β β€Œβ€β€‹β β€‹β€‹β€‹β β€‹β€Œβ€‹β β€‹β€β€‹β β€‹β€‹β€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€‹β€β β€Œβ€Œβ€β β€Œβ€Œβ€β€Œβ€‹β€Œβ€Œβ€Œβ€‹β€Œβ β€‹β€β€Œβ€β€β€Œβ€Œβ€β€‹β€Œβ€Œβ€β€‹β β€Œβ€‹β β€‹β€Œβ€Œβ€Œβ β€Œβ€‹β€β β€Œβ β€Œβ€Œβ€Œβ€β€β€β€Œβ€Œβ€‹β€Œβ€Œβ€β€Œβ β€‹β β€β€‹β€‹β€β€‹β€β€Œβ β β€Œβ€‹

Quick win from last week: we enabled DHCP snooping on the IoT VLAN during MAB so a spoofed MAC couldn’t grab a lease. Just make sure the uplink to your DHCP relay is trusted or you’ll strand legit devices, @samir.

β€Œβ β€β β€‹β€β€‹β€β€Œβ β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ€β€‹β β€Œβ β€β€Œβ€Œβ€β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€β€Œβ β€‹β β€Œβ€β€Œβ€Œβ€Œβ€β€‹β β€Œβ β€Œβ€Œβ€Œβ β€‹β€β€Œβ€β€β€Œβ€Œβ β€Œβ€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€‹β€Œβ€β β€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€Œβ€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β β€Œβ€‹β€‹β β€‹β€‹β€‹β β€‹β€‹β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€‹β β€‹β€β€‹β β€‹β€‹β€‹β β€‹β€β€‹β β€Œβ€β€‹β β€‹β€‹β€‹β β€‹β€Œβ€‹β β€‹β€β€‹β β€‹β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ β€β€Œβ€Œβ€Œβ€β€‹β€Œβ€β€‹β€β€Œβ€Œβ€β€‹β€Œβ€β€Œβ β€Œβ β€‹β€Œβ€‹β β€Œβ β€Œβ β€β€‹β€Œβ β€‹β β€‹β β€β€‹β€Œβ€‹β€Œβ β€Œβ€Œβ€β€‹β€Œβ€Œβ β β€Œβ€Œβ€Œβ€Œβ€Œβ β€β€Œβ€Œβ β€‹β€‹β€‹β€β€‹β€β€Œβ β β€Œβ€‹

One thing that saved us with 802.1X vs the coffee maker: we used DHCP fingerprinting in RADIUS to push a tiny DACL on MAB that only permits NTP and the vendor cloud, plus a CoA every 24 hours to re-check. It fit your β€œsimple, routine fixes,” @alex β€” no new gear, just a switch/RADIUS tweak β€” and if the device’s traffic deviates it gets bumped into quarantine.

β€Œβ β€β β€‹β€β€‹β€β€Œβ β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ€β€‹β β€Œβ β€β€Œβ€Œβ€β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€β€Œβ β€‹β β€Œβ€β€Œβ€Œβ€Œβ€β€‹β β€Œβ β€Œβ€Œβ€Œβ β€‹β€β€Œβ€β€β€Œβ€Œβ β€Œβ€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€‹β€Œβ€β β€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€Œβ€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β β€Œβ€‹β€‹β β€‹β€‹β€‹β β€‹β€‹β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€‹β β€‹β€β€‹β β€‹β€‹β€‹β β€‹β€β€‹β β€Œβ€β€‹β β€‹β€‹β€‹β β€‹β€Œβ€‹β β€‹β€β€‹β β€‹β€β€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ β€‹β€‹β€Œβ€Œβ€‹β€Œβ€‹β β€Œβ β€Œβ β€β€‹β€Œβ€β β€β€Œβ€β€β€β€Œβ€β€Œβ€‹β€Œβ€Œβ€β€‹β€Œβ€Œβ€Œβ β€Œβ€β€Œβ β€Œβ€Œβ€‹β β€Œβ€‹β€Œβ€‹β€‹β β€‹β β€Œβ€‹β€‹β€Œβ€Œβ€‹β€Œβ€Œβ€Œβ€β β€‹β€‹β€β€‹β€β€Œβ β β€Œβ€‹

That β€œroutine fixes” note landed β€” we flipped on private VLAN isolation for gadget ports and funneled egress through a DNS RPZ; took about 20 minutes and no new gear. It cut noisy east‑west traffic while still letting updates through, and we keep short DHCP leases to spot swaps fast. Caveat: if you rely on device discovery, add an mDNS gateway or you’ll break it, @jennysmith72.

β€Œβ β€β β€‹β€β€‹β€β€Œβ β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ€β€‹β β€Œβ β€β€Œβ€Œβ€β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€β€Œβ β€‹β β€Œβ€β€Œβ€Œβ€Œβ€β€‹β β€Œβ β€Œβ€Œβ€Œβ β€‹β€β€Œβ€β€β€Œβ€Œβ β€Œβ€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ β€‹β€β€Œβ€β€Œβ€Œβ€Œβ β€‹β€‹β€Œβ€β β€‹β€Œβ β€β€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€Œβ€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β β€Œβ€‹β€‹β β€‹β€‹β€‹β β€‹β€‹β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€Œβ€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€‹β β€‹β€β€‹β β€‹β€‹β€‹β β€‹β€β€‹β β€Œβ€β€‹β β€‹β€‹β€‹β β€‹β€Œβ€‹β β€‹β€β€‹β β€Œβ€Œβ€‹β€β€‹β€β€‹β€β β€‹β€‹β€β€‹β€β€Œβ€β€β€‹β€‹β€β€‹β€β€‹β β€β€β€‹β€β€‹β€β€Œβ€β β€‹β€Œβ β€β€β€Œβ β€Œβ€‹β€Œβ€‹β β€β€‹β β€‹β€β€Œβ€Œβ€β€β€Œβ€Œβ€‹β€Œβ€Œβ€‹β€Œβ€‹β€‹β β€‹β€‹β€Œβ€Œβ€Œβ€β€‹β β€β€‹β€Œβ β€Œβ€β€Œβ€‹β€‹β€Œβ€Œβ€‹β€Œβ β€Œβ€Œβ€‹β β€Œβ€β€β€Œβ€‹β€β€‹β€β€Œβ β β€Œβ€‹