New Windows Defender Zero-Day Blocks AV Updates
Naceri released BigDiskBuster, a zero-day PoC that blocks Windows Defender from updating on all supported Windows. No patch and no CVE assigned.

Researcher Abdelhamid Naceri, who publishes under the alias Nightmare Eclipse, released a proof-of-concept tool called BigDiskBuster over the weekend. It blocks Windows Defender from downloading platform and signature updates. Confirmed scope: all supported Windows versions. Microsoft has not issued a patch or assigned a CVE number as of publication.
Naceri described the behavior directly: “completely denies defender from updating so you’re stuck with your current version if the tool is running in the background.” Source: BleepingComputer.
The practical exposure is a stale definition database on any machine where the tool runs in the background. Endpoints relying on Defender as their primary antivirus stop receiving new threat signatures from the moment it starts.
This is not Naceri’s first public Defender zero-day. An earlier tool, UnDefend, appeared in April 2026 with similar update-blocking behavior. Naceri’s broader disclosure track covers ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma; Microsoft has patched some of them, and others remain unaddressed. Earlier this month, Naceri dropped ShieldCrash, which carried its own Defender attack surface.
For context on Microsoft’s current patch cadence: the September Patch Tuesday addressed 974 vulnerabilities, including two zero-days confirmed as actively exploited, though BigDiskBuster was not part of that cycle.
Confidence on affected scope: confirmed, based on researcher disclosure and independent press verification. Microsoft response timeline: unconfirmed. Defenders monitoring for anomalous Defender update failures should check Windows Event Viewer for Security Center update errors (events 1008, 2001) without a clear network explanation; process-level monitoring can verify whether an unauthorized tool is responsible.
Found this useful? Share it.


