BigDiskBuster zero-day blocks Windows Defender updates

BigDiskBuster zero-day blocks Windows Defender updates

Researcher Abdelhamid Naceri released BigDiskBuster, a Windows Defender zero-day that blocks antivirus updates and leaves machines on old definitions.

A researcher has published a new Windows Defender zero-day exploit called BigDiskBuster that blocks antivirus updates inside Microsoft Defender, the security software built into Windows. The tool appeared over the weekend and comes from Abdelhamid Naceri, a security researcher who also works under the name Nightmare Eclipse; the release was reported by BleepingComputer in an article by Sergiu Gatlan dated September 22, 2026. A zero-day is a security flaw that becomes public before the vendor has a fix ready, and that is the case here: the report notes that BigDiskBuster has no official patch, and a Microsoft spokesperson was not immediately available to comment when BleepingComputer asked about it.

According to the researcher, the tool stops Defender from carrying out platform and signature updates. Signature updates, often called definition updates, are the small data files that tell an antivirus program what the newest malicious software looks like; without them, a computer recognises only the threats it already knew about. Naceri said BigDiskBuster has to run in the background to have that effect, and that while it is running the machine is 'stuck with your current version'. He described the release as a proof of concept, meaning a demonstration rather than finished software, and said it appears to work on all supported versions of Windows, although he added that it is a bit buggy and needs rewriting.

BigDiskBuster follows UnDefend, an earlier Defender zero-day from the same researcher released in April, which allowed standard users, meaning ordinary accounts without administrator rights, to block definition updates. Since April 2026, Naceri has released close to a dozen zero-day exploits, a run that the report ties to an ongoing dispute with Microsoft over what he describes as his unfair termination in March 2025. The tools disclosed this year include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma and UnDefend, aimed at Microsoft Defender, at BitLocker (the Windows feature that encrypts the contents of a disk) and at other Windows components.

One of the most powerful items in the series is ShieldCrash, published two weeks before BigDiskBuster, just after Microsoft shipped its monthly Patch Tuesday security updates. Patch Tuesday is the day each month when Microsoft releases its fixes. ShieldCrash grants SYSTEM access, the highest permission level on a Windows computer, which in practice means full control of the machine. According to Naceri, ShieldCrash bypasses ShieldBreak, a Defender privilege escalation flaw (a bug that lets someone gain rights they should not have) that Microsoft had patched a week earlier, and ShieldBreak in turn bypassed RoguePlanet, another Defender flaw the researcher disclosed in June and Microsoft patched in July.

Microsoft's first response to the disclosures was a warning of legal action against anyone engaged in activity that causes real harm to its customers, wording that led many people in the information security community to read it as a direct threat to the researcher. The company has since fixed several of the flaws he reported, among them ShieldBreak, RoguePlanet, YellowKey, GreenPlasma and MiniPlasma. Others, including the freshly published BigDiskBuster, still have no official patch.

For site owners and IT teams, the practical impact is narrower than a full break-in but still deserves attention. BleepingComputer describes BigDiskBuster as a denial-of-service zero-day: it does not by itself give an intruder access to a computer, but it can hold an antivirus engine at an old version, and protection that never learns about new malicious software will not recognise it. Windows Security, the dashboard built into Windows, shows the date of the last definition update, so a frozen date is how a stalled engine would become visible. Because the tool has to run to have any effect, someone must be able to launch it on the machine, which makes shared laptops and computers where software from unknown sources gets executed the places where the risk is greatest. It is not yet known whether Microsoft intends to patch this particular flaw, and the researcher himself has said his proof of concept is not finished software.

Readers who would rather not take on another patching routine can look at AEU Hosting (albhosting.eu), a managed WordPress hosting service where the upkeep of the platform, including its security updates, is handled for the customer. The wider lesson of this story applies to laptops and to websites alike: an update that never arrives is a defence that quietly stops working, and the only way to notice is to check which version you are actually running.

How to Protect Yourself

  1. Open Windows Security on your computer, click Virus and threat protection, and check that the definition date shown there is recent, because a date that stays frozen is the sign this kind of tool would leave behind.
  2. Leave Windows Update switched on automatic and restart your computer when it asks you to, so the fixes Microsoft releases actually reach your machine.
  3. Never run tools or programs from the internet that claim to block, change or speed up your antivirus, even if they look like harmless demos.
  4. Give every person who uses a computer their own user account, so it is harder for an unauthorised program to be started on it.
  5. Keep a backup copy of your important files on a separate drive or in cloud storage, so a machine that quietly stopped receiving protection cannot cost you your data.
  6. If you manage computers for a business, ask your IT provider how they check that antivirus updates are still arriving on every device.

Terms Explained

  • zero-day A security hole in software that becomes public before the maker has a fix ready, so anyone can use it in the meantime.
  • Microsoft Defender The free antivirus program that comes built into Windows and protects the computer from viruses and other harmful software.
  • signature updates Small data files an antivirus downloads regularly to learn what the newest viruses look like, also called definition updates.
  • proof of concept A demonstration program made to show that a security problem is real, rather than a finished tool meant for everyday use.
  • privilege escalation A flaw that lets a user of a computer gain rights they are not supposed to have, such as full control of the machine.
  • Patch Tuesday The fixed day each month when Microsoft releases its security fixes for Windows and its other products.
  • BitLocker A Windows feature that scrambles the contents of a hard disk so that nobody can read it without the right key.
  • denial-of-service An attack or tool that stops a service from working properly, for example by preventing an antivirus from updating.

Related AEU services

  • AEU-I IT and security consulting