Protect.Computer
NEWS

BigDiskBuster Zero-Day Lets Attackers Block Windows Defender Updates

· 1 min read · Malicious byte Device safety
BigDiskBuster Zero-Day Lets Attackers Block Windows Defender Updates

Security researcher Abdelhamid Naceri — known online as Nightmare Eclipse — released a new Windows Defender zero-day exploit over the weekend. Named BigDiskBuster, it runs in the background and prevents Microsoft Defender Antivirus from downloading signature and platform updates, effectively freezing the antivirus at whatever definitions it had when the tool started.

Naceri describes it as similar to UnDefend, a Defender zero-day he released in April 2026 that blocked definition updates. BigDiskBuster is reportedly more complete: it blocks both signature and platform updates and works across all currently supported Windows versions. A running BigDiskBuster process means Defender can’t learn about new malware, which in practice means new threats released after the freeze point will go undetected. The exploit is publicly available, making it easy for malware authors to incorporate it into attack chains. BigDiskBuster is the latest in a string of roughly a dozen Defender and Windows zero-days Naceri has released this year — including ShieldCrash, ShieldBreak, LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend — as part of an ongoing public dispute with Microsoft over his alleged termination in March 2025. Microsoft has patched some of them but has not commented on BigDiskBuster and has not issued a patch.

How to check if you’re affected

Affected versions include all supported Windows releases (Windows 10 and Windows 11). Defender’s update status is visible in Windows Security → Virus & threat protection → Virus & threat protection updates. If “Last update” is stuck at a date days in the past and you’re connected to the internet, BigDiskBuster or similar interference may be at play. Running a full scan with Windows Security and checking Event Viewer (Applications and Services Logs → Microsoft → Windows → Windows Defender → Operational) for update-failure events will confirm whether Defender is being blocked.

Sources

Related reading