Putting your smart bulbs, thermostats, and cameras on a separate VLAN is a great first step — but it doesn't stop them from attacking each other. This episode unpacks the overlooked gap in IoT network security: intra-VLAN lateral movement. We break down how client isolation (also called station-to-station blocking or Private VLANs) works at layer two, why it's not enabled by default, and what breaks when you flip the switch. From CISA advisories to CVE-2024-23897, we explore why the real threat isn't your router — it's the thirty devices with Wi-Fi chips sitting inside your network. Plus, the practical tradeoffs: hub-and-spoke architectures, broken mDNS discovery, and how to lock down lateral movement without breaking your smart home.