Rebranded feature promises household alerts without video, but mind the small print

Comcast has integrated its Wi-Fi-based motion detection feature, previously known as WiFi Motion, into a new offering called Xfinity Shield. This repackaged bundle combines physical and cybersecurity services, including protections built into the Xfinity Gateway router. The original WiFi Motion service was launched by the US telecommunications company in 2025.
The Wi-Fi sensing technology operates by utilizing radio waves within a user's home to detect movement. Comcast explains that the Xfinity Gateway intelligence identifies changes in the radio frequency signal between the Gateway and other connected Wi-Fi devices. When unexpected activity is detected, instant notifications are sent to users via the Xfinity app.
Comcast emphasizes that this feature provides an additional layer of awareness without recording video, capturing images, or identifying individuals. The company does not classify it as a home security service, but rather a feature, as it is not managed by a dedicated security provider.
For the sensing feature to function, it requires the Xfinity Gateway, Xfinity Wi-Fi extenders, and up to three other compatible, stationary devices such as thermostats or home speakers. Mobile devices like smartphones are not suitable. Users are advised to position their router and extenders to ensure signals pass through desired detection areas, with open spaces like hallways yielding the best results. Regular testing is recommended to maintain coverage.
The Xfinity app includes settings to customize the motion detection. A "small pets" setting can be enabled to ignore animals weighing approximately 18 kg (40 pounds) or less, though the app warns this may also exclude small children. Users can also adjust sensitivity levels to low, medium, or high. High sensitivity is recommended for single-family, detached homes, while lower settings may be preferable for those in shared-wall residences to prevent unnecessary alerts.
Comcast assures customers that WiFi Motion does not track individuals or their precise movements, nor can it identify specific people. The company also states it "does not monitor motion and/or notifications generated by the service." However, fine print accompanying the service, which was also present at its 2025 launch, indicates potential privacy limitations.
The terms state: "Subject to applicable law, Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena." Comcast has not specified what information might be disclosed or which "third parties" beyond law enforcement could receive it.
Users can define "sensing areas" by strategically placing Wi-Fi devices in high-traffic parts of their homes. Comcast describes these areas as long ovals extending between two connected devices. While sensing areas can extend through walls, in multi-story homes, customers are encouraged to avoid placing Wi-Fi equipment directly above or below each other. Motion is detected when movement disrupts the wireless signals traveling between the Xfinity Wi-Fi equipment and selected connected devices within these defined sensing areas, triggering notifications.
Comcast is not the first to implement Wi-Fi radio wave motion detection. Companies like Cognitive Systems and Origin Wireless have been developing similar applications. Beyond home security, this technology can be used for occupancy measurement and foot traffic analysis in commercial buildings, potentially aiding in energy reduction and space optimization. It also holds promise for elder care, where Wi-Fi transmissions can track activity patterns to assess fall risks.
The development of an official Wi-Fi sensing standard began in 2020. The IEEE published a draft in 2023, and the 802.11bf standard was ratified in 2025. Major chip manufacturers, including MediaTek and Qualcomm, are reportedly working to integrate this standard into their Wi-Fi 7 chips and future iterations. Plume, a SaaS provider of smart home services, has offered Wi-Fi sensing since 2020, around the time the 802.11bf working group commenced its standardization efforts.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed