Researcher Unveils BigDiskBuster Zero-Day That Halts Windows Defender Updates
Security researcher Abdelhamid Naceri, also known as Nightmare Eclipse, releases a new Windows Defender zero-day exploit called BigDiskBuster that blocks Microsoft's antivirus from receiving updates. Naceri says the proof of concept runs in the background and prevents Defender from performing platform and signature updates, leaving users stuck with their current version while the tool is active. He describes it as similar to an earlier Defender zero-day he released in April, known as UnDefend, which also allowed standard users to block definition updates.
According to Naceri, BigDiskBuster works on all supported Windows versions, though he notes the proof of concept is somewhat buggy and needs rewriting. The release is the latest move in an ongoing dispute between the researcher and Microsoft over his alleged unfair termination in March 2025. Since April 2026, Naceri has released nearly a dozen zero-day exploits targeting Microsoft Defender, BitLocker, and other Windows components, including ShieldCrash, LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and RoguePlanet.
Microsoft has patched several of the flaws Naceri disclosed, such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, but other security issues remain without an official fix. The company previously warns of legal action against anyone engaging in malicious activity that causes real harm to its customers, a statement many in the infosec community interpret as a direct threat against the researcher. Microsoft is not immediately available for comment when asked about the BigDiskBuster denial-of-service zero-day.