LIVE · cybersecurity feed
Live wire
security

Comcast gives its Wi-Fi motion detector a security makeover

Rebranded feature promises household alerts without video, but mind the small print

zeroday.news ·

Comcast has integrated its Wi-Fi-based motion detection feature, previously known as WiFi Motion, into a new offering called Xfinity Shield. This repackaged bundle combines physical and cybersecurity services, including protections built into the Xfinity Gateway router. The original WiFi Motion service was launched by the US telecommunications company in 2025.

The Wi-Fi sensing technology operates by utilizing radio waves within a user's home to detect movement. Comcast explains that the Xfinity Gateway intelligence identifies changes in the radio frequency signal between the Gateway and other connected Wi-Fi devices. When unexpected activity is detected, instant notifications are sent to users via the Xfinity app.

Comcast emphasizes that this feature provides an additional layer of awareness without recording video, capturing images, or identifying individuals. The company does not classify it as a home security service, but rather a feature, as it is not managed by a dedicated security provider.

For the sensing feature to function, it requires the Xfinity Gateway, Xfinity Wi-Fi extenders, and up to three other compatible, stationary devices such as thermostats or home speakers. Mobile devices like smartphones are not suitable. Users are advised to position their router and extenders to ensure signals pass through desired detection areas, with open spaces like hallways yielding the best results. Regular testing is recommended to maintain coverage.

The Xfinity app includes settings to customize the motion detection. A "small pets" setting can be enabled to ignore animals weighing approximately 18 kg (40 pounds) or less, though the app warns this may also exclude small children. Users can also adjust sensitivity levels to low, medium, or high. High sensitivity is recommended for single-family, detached homes, while lower settings may be preferable for those in shared-wall residences to prevent unnecessary alerts.

Comcast assures customers that WiFi Motion does not track individuals or their precise movements, nor can it identify specific people. The company also states it "does not monitor motion and/or notifications generated by the service." However, fine print accompanying the service, which was also present at its 2025 launch, indicates potential privacy limitations.

The terms state: "Subject to applicable law, Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena." Comcast has not specified what information might be disclosed or which "third parties" beyond law enforcement could receive it.

Users can define "sensing areas" by strategically placing Wi-Fi devices in high-traffic parts of their homes. Comcast describes these areas as long ovals extending between two connected devices. While sensing areas can extend through walls, in multi-story homes, customers are encouraged to avoid placing Wi-Fi equipment directly above or below each other. Motion is detected when movement disrupts the wireless signals traveling between the Xfinity Wi-Fi equipment and selected connected devices within these defined sensing areas, triggering notifications.

Comcast is not the first to implement Wi-Fi radio wave motion detection. Companies like Cognitive Systems and Origin Wireless have been developing similar applications. Beyond home security, this technology can be used for occupancy measurement and foot traffic analysis in commercial buildings, potentially aiding in energy reduction and space optimization. It also holds promise for elder care, where Wi-Fi transmissions can track activity patterns to assess fall risks.

The development of an official Wi-Fi sensing standard began in 2020. The IEEE published a draft in 2023, and the 802.11bf standard was ratified in 2025. Major chip manufacturers, including MediaTek and Qualcomm, are reportedly working to integrate this standard into their Wi-Fi 7 chips and future iterations. Plume, a SaaS provider of smart home services, has offered Wi-Fi sensing since 2020, around the time the 802.11bf working group commenced its standardization efforts.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

The long tail of Clop’s PTC hack is just beginning to emerge

The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims. The post The long tail of Clop’s PTC hack is just beginning to emerge appeared first on CyberScoop.

cloud

Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)

Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the data is more or less harmless, such as the region the machine is running in or its MAC and IP addresses. However, the service may also be used to retrieve credentials for IAM roles and service account tokens.

security

Password spraying attacks surge 155x as hackers exploit MFA gaps

Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]

vulnerabilitycritical

Oracle Critical Patch Update, August 2026 Security Update Review

Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products. In this Oracle Critical Patch Update, Oracle Fusion Middleware and Oracle

security

Virtual Event Today: CodeSecCon – Secure Your Code and Applications

CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained. The post Virtual Event Today: CodeSecCon – Secure Your Code and Applications appeared first on SecurityWeek.

breach

US charges Iranians for sprawling hacking campaign on government agencies, universities

The Justice Department accused 17 alleged hackers with ties to the Iranian government of breaching email accounts at U.S. government agencies and stealing intellectual property from dozens of universities.