MikhbarMIKHBAR
Cybersecurity

New Microsoft Defender Zero-Day Blocks Antivirus Updates

A researcher has unveiled a new zero-day exploit capable of blocking critical Microsoft Defender updates across all supported versions of Windows. This latest release is part of a series of disclosures stemming from an ongoing dispute with Microsoft.

New Microsoft Defender Zero-Day Blocks Antivirus Updates

BigDiskBuster Exploit Surfaces

Security researcher Abdelhamid Naceri, also known as Nightmare Eclipse, has released a new zero-day exploit targeting Microsoft Defender. The tool, dubbed BigDiskBuster, is designed to disrupt the antivirus software's ability to receive security and definition updates. According to a report by BleepingComputer, this exploit requires the tool to remain active in the background to function effectively, effectively freezing the antivirus at its current version.

Naceri described the functionality of the tool in a recent post, stating that he made a funny tool that completely denies Defender from updating. The researcher noted that while the current proof of concept is somewhat buggy and requires additional refinement, it clearly demonstrates the mechanism for blocking platform and signature updates on all supported Windows versions.

Context of the Research and Dispute

The emergence of BigDiskBuster is the latest chapter in a broader series of security disclosures tied to a personal dispute. Since April 2026, Naceri has released almost a dozen zero-day exploits targeting various Windows components, including BitLocker and Microsoft Defender. These actions are reportedly linked to the researcher's contention regarding their alleged unfair termination from Microsoft in March 2025.

The researcher has previously developed other tools of a similar nature, such as UnDefend, which was released in April. That earlier tool established a precedent for allowing standard users to interfere with the update cycles of security definitions. Naceri confirmed that the current BigDiskBuster exploit utilizes a similar methodology to deny updates, keeping a system stuck with its current version for as long as the malicious process remains active.

BigDiskBuster tweet
Image related to the report from BleepingComputer · Source: BleepingComputer

A Growing List of Vulnerabilities

The frequency of these releases has accelerated in recent months. Only two weeks prior to this incident, Naceri released an exploit named ShieldCrash, which grants SYSTEM-level privileges. This came shortly after Microsoft had addressed other security flaws. The researcher stated that ShieldCrash was engineered to bypass a previously known vulnerability, ShieldBreak, which Microsoft had attempted to mitigate just a week earlier.

Throughout the year, Naceri has disclosed multiple flaws, including those labeled LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, and MiniPlasma. While Microsoft has taken action to resolve some of these, such as issuing updates for the flaws identified in the CVE-2026-69414 advisory, other vulnerabilities remain unpatched.

Microsoft’s Stance and Future Outlook

Microsoft has not remained silent regarding this influx of disclosures. The company previously issued warnings suggesting that they might pursue legal action against individuals engaged in malicious activity that causes real harm to customers. This stance led to speculation within the cybersecurity community that the company was directing threats toward the researcher. As of the latest report, a Microsoft spokesperson was not available to provide a comment specifically addressing the BigDiskBuster denial-of-service zero-day.

Sources

  • BleepingComputerNew Windows Defender zero-day blocks Microsoft antivirus updates