Researcher Releases New Windows Defender Zero-Day That Blocks Antivirus Updates

BigDiskBuster exploit is the latest in a series of nearly a dozen flaws released amid an ongoing dispute with Microsoft

By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Security researcher Abdelhamid Naceri, also known as Nightmare Eclipse, released a new Microsoft Defender zero-day exploit over the weekend that blocks the antivirus software from performing platform and signature updates. Dubbed BigDiskBuster, the proof-of-concept tool works on all supported Windows versions and must run in the background to prevent Defender from updating, leaving systems with outdated protections.

The BigDiskBuster exploit is similar to another Defender zero-day called UnDefend, which Naceri released in April 2026 and that also allowed standard users to block definition updates. In a social media post, Naceri described the tool as a 'funny tool' that denies Defender from updating, though he noted the proof-of-concept is 'a bit buggy and needs some rewriting.'

Since April, Naceri has disclosed nearly a dozen Windows zero-day vulnerabilities as part of an ongoing dispute with Microsoft over what he claims was his unfair termination from the company in March 2025. Two weeks ago, he released a separate Defender zero-day exploit called ShieldCrash that grants SYSTEM access, shortly after Microsoft patched a related flaw known as ShieldBreak. Earlier in the year, he published the RoguePlanet exploit, which Microsoft fixed in July.

The researcher has published the BigDiskBuster code on GitHub, making it publicly available. Microsoft has not yet responded to the latest disclosure, and it remains to be seen when the company will issue a patch. The exploit does not directly compromise systems but prevents Defender from receiving updates, potentially exposing users to new and unaddressed threats.

§

Analysis

Why This Matters

  • Windows users relying on Microsoft Defender could remain unprotected if BigDiskBuster is deployed, as it blocks all signature and platform updates.
  • The ongoing release of zero-days by a former employee highlights potential risks when security researchers turn against a vendor.
  • With nearly a dozen flaws disclosed in months, Microsoft faces increasing pressure to address the dispute and patch vulnerabilities quickly.

Background

Abdelhamid Naceri (Nightmare Eclipse) began releasing Windows zero-days publicly in April 2026, claiming Microsoft unfairly terminated him in March 2025. His exploits have targeted Microsoft Defender with increasing sophistication, each one bypassing previous patches. Earlier examples include UnDefend, RoguePlanet (patched July 2026), ShieldBreak (patched September 2026), and ShieldCrash. The latest, BigDiskBuster, focuses on preventing Defender updates rather than privilege escalation.

Key Perspectives

Abdelhamid Naceri: Believes his termination was unjust and is publicly disclosing vulnerabilities to pressure Microsoft. He characterizes the tools as proofs of concept intended to demonstrate flaws. Microsoft: Has been patching flaws as they emerge, but the pace of new disclosures means some exploits remain unaddressed for weeks. The company does not typically comment on individual researcher disputes. End users and security community: Rely on timely patches for protection. Naceri's releases, while demonstrating technical skill, risk being weaponised before fixes are available. Users may need to consider supplementary or alternative antivirus solutions.

What to Watch

  • Microsoft's next Patch Tuesday (likely October 2026) for a fix to BigDiskBuster.
  • Whether Naceri releases further exploits or begins targeting other Windows components.
  • Reports of BigDiskBuster being used in real-world attacks, which would escalate the situation from proof-of-concept to active threat.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.