2026-01-26 – Weekly Cybersecurity News : Coffee machine tried to BGP peer

Last week in our cybersecurity forum, members delved into some pressing topics. Discussions were rich with practical advice on control mapping to meet audit requirements and optimizing security investments as contract renewals approach. There was a lively thread about unexpected network behavior from IoT devices, sparked by a quirky incident involving a coffee machine. Additionally, the community shared strategies for effective alert triage and the importance of small controls in preventing large-scale security incidents.


This Week’s Hot Topics

  • Audit-ready control mapping resources
    A practical discussion on tools and frameworks to streamline control mapping for audits. Useful for those preparing for compliance checks.
    Read more here

  • Coffee machine tried to BGP peer
    A humorous yet serious look at unexpected network traffic from IoT devices. A reminder of the complexities in securing smart devices.
    Read more here

  • Right-size security before renewals hit
    Tips on evaluating and adjusting security measures to avoid unnecessary costs before renewal periods.
    Read more here

  • Small control, huge blast radius
    Insights into how seemingly minor controls can have significant impacts on security posture.
    Read more here

  • Start with alert triage and a playbook
    A guide for building effective alert triage processes and incident response playbooks, crucial for swift threat management.
    Read more here

  • Looking for hands-on malware defense training
    Community members are sharing recommendations for practical malware defense courses.
    Read more here

  • Alert triage and incident drills for beginners
    A perfect starting point for those new to incident response, focusing on practical drills and triage methods.
    Read more here

  • Right-sizing EDR for 400 endpoints
    Discussing strategies to tailor endpoint detection and response solutions for medium-sized environments.
    Read more here

  • Beyond CVSS: practical vuln triage
    Exploring methods for assessing vulnerabilities beyond standard scoring systems like CVSS.
    Read more here

  • Mundane fixes that avert big breaches
    Highlighting basic security measures that have proven effective in preventing major breaches.
    Read more here


Thanks for keeping the conversation going and contributing your expertise. Have a great week ahead in cybersecurity.

We saw this: coffee machine BGP attempt; pfSense VLAN + egress allowlist + ‘block 179’ fixed it; allow NTP.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠​‌​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌​⁠‍‌⁠‍​‌​​‍‌​⁠‌​‍⁠‌‌⁠‍‌‌‌‌‍‌‌‌‍​⁠​​‌‌‌‌‌⁠​​‌‍⁠‍‌‍‌‌‌‌​⁠​⁠​⁠‌⁠​‍​‍​‍‌⁠⁠‌​

Saw a smart TV randomly knock on TCP/179 once — apparently it wanted an ASN… What stuck was dropping unknown egress by policy and running Zeek on a mirror port to alert on “new outbound ports” from the IoT VLAN (https://zeek.org). Caveat: some devices hardcode NTP, so I NAT-redirect 123/UDP to our internal time source instead of opening it up.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠​‌​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‌​⁠​‍​⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​⁠‍​‌‍‍​‌​‍‍‌‌‌⁠‌​⁠​‌​‌⁠‌⁠​​‌​​⁠​⁠​‌‌​‍​​⁠​‍‌‍‍‌‌‍​⁠‌‍‌⁠‌‍‍⁠‌⁠‌​​‍​‍‌⁠⁠‌​

But had a badge printer light up TCP/179 during that same ‘unexpected network behavior’ week — . What finally stuck was 802.1X/MAB into an IoT VLAN plus MUD-based egress (RFC 8520: RFC 8520 - Manufacturer Usage Description Specification) so the switch auto-quarantines anything outside its declared flows; bonus: it made audit control mapping easier. If a device doesn’t support MUD, FQDN egress rules at the edge are a decent fallback — anyone rolling that into renewal talks right now?

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌⁠​‍‌‍‌‌‌⁠​​‌‍⁠​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​⁠‌​​⁠​‌​⁠‌​​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‍​⁠​​​⁠​‍​⁠​​​⁠​‌​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍‌⁠‌‍‌⁠‍‌‌‍⁠‍‌⁠‍​‌​⁠​‌‍⁠‌‌​⁠‍‌‌‍​‌​‌‍‌​​‍‌​‍​‌​⁠⁠​⁠‍​‌​‌⁠​⁠‌‍​⁠​‌​‍​‍‌⁠⁠‌​