Over the weekend, security researcher Abdelhamid Naceri, known in the cybersecurity community as Nightmare Eclipse, unveiled a new zero-day exploit targeting Microsoft Defender. Dubbed BigDiskBuster, this tool is designed to obstruct antivirus updates, thereby leaving systems vulnerable to potential threats.
Details of the Exploit
Naceri describes BigDiskBuster as akin to a previous exploit he released in April, named UnDefend, which similarly allowed standard users to halt definition updates. According to him, BigDiskBuster operates across all supported versions of Windows, requiring it to run in the background to effectively block Defender updates.
In his own words, Naceri remarked, “Made a funny tool, completely denies defender from updating so you’re stuck with your current version if the tool is running in the background.” He further elaborated that while this proof of concept is reminiscent of UnDefend, it is somewhat buggy and may require further refinement. “Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewriting but you get the idea,” he added.
A History of Controversy
Since April 2026, Naceri, who claims to have previously worked at Microsoft, has released nearly a dozen zero-day exploits amid an ongoing dispute with the tech giant over what he alleges was an unfair termination in March 2025. His portfolio includes several exploits that enabled privilege escalation on various Windows versions five years ago.
Just two weeks prior to the release of BigDiskBuster, Naceri introduced another Defender zero-day exploit named ‘ShieldCrash.’ This tool grants SYSTEM access and emerged shortly after Microsoft deployed its monthly Patch Tuesday security updates. Naceri asserts that ShieldCrash circumvents a previously patched flaw known as ShieldBreak, which itself had bypassed another vulnerability, RoguePlanet, disclosed in June and patched by Microsoft in July.
Ongoing Security Concerns
Naceri’s recent exploits this year also encompass a range of creatively named tools, including LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, all targeting Microsoft Defender, BitLocker, and other Windows components.
In response to Naceri’s activities, Microsoft initially issued warnings of potential legal action against individuals engaging in “malicious activity causing real harm” to its customers. This led many within the information security community to speculate that Microsoft was directly addressing the researcher.
While Microsoft has addressed some of the vulnerabilities disclosed by Naceri, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, several other security issues remain without official patches. As of now, a Microsoft spokesperson has not provided any comments regarding the newly released BigDiskBuster denial-of-service zero-day when approached by BleepingComputer.
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri, known in the cybersecurity community as Nightmare Eclipse, unveiled a new zero-day exploit targeting Microsoft Defender. Dubbed BigDiskBuster, this tool is designed to obstruct antivirus updates, thereby leaving systems vulnerable to potential threats.
Details of the Exploit
Naceri describes BigDiskBuster as akin to a previous exploit he released in April, named UnDefend, which similarly allowed standard users to halt definition updates. According to him, BigDiskBuster operates across all supported versions of Windows, requiring it to run in the background to effectively block Defender updates.
In his own words, Naceri remarked, “Made a funny tool, completely denies defender from updating so you’re stuck with your current version if the tool is running in the background.” He further elaborated that while this proof of concept is reminiscent of UnDefend, it is somewhat buggy and may require further refinement. “Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewriting but you get the idea,” he added.
A History of Controversy
Since April 2026, Naceri, who claims to have previously worked at Microsoft, has released nearly a dozen zero-day exploits amid an ongoing dispute with the tech giant over what he alleges was an unfair termination in March 2025. His portfolio includes several exploits that enabled privilege escalation on various Windows versions five years ago.
Just two weeks prior to the release of BigDiskBuster, Naceri introduced another Defender zero-day exploit named ‘ShieldCrash.’ This tool grants SYSTEM access and emerged shortly after Microsoft deployed its monthly Patch Tuesday security updates. Naceri asserts that ShieldCrash circumvents a previously patched flaw known as ShieldBreak, which itself had bypassed another vulnerability, RoguePlanet, disclosed in June and patched by Microsoft in July.
Ongoing Security Concerns
Naceri’s recent exploits this year also encompass a range of creatively named tools, including LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, all targeting Microsoft Defender, BitLocker, and other Windows components.
In response to Naceri’s activities, Microsoft initially issued warnings of potential legal action against individuals engaging in “malicious activity causing real harm” to its customers. This led many within the information security community to speculate that Microsoft was directly addressing the researcher.
While Microsoft has addressed some of the vulnerabilities disclosed by Naceri, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, several other security issues remain without official patches. As of now, a Microsoft spokesperson has not provided any comments regarding the newly released BigDiskBuster denial-of-service zero-day when approached by BleepingComputer.