New Windows Defender zero-day blocks Microsoft antivirus updates

Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates.
Naceri named it BigDiskBuster and said it is similar to another Defender zero-day known as UnDefend, which he released in April and that allowed standard users to block definition updates.
The security researcher added that BigDiskBuster works on all supported Windows versions and that it needs to run in the background to block Defender updates.
"Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," he said.
"This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea."
Since April 2026, Naceri, who claims to be a former Microsoft employee, has released almost a dozen zero-day exploits as part of an ongoing dispute with Microsoft over their alleged unfair termination in March 2025.
Naceri also released several zero-day exploits that allowed privilege escalation on various Windows versions five years ago.
Two weeks ago, they released another Defender zero-day exploit that grants SYSTEM access (known as 'ShieldCrash') right after Microsoft rolled out this month's Patch Tuesday security updates.
According to Naceri, ShieldCrash bypasses another ShieldBreak Defender privilege escalation flaw patched a week earlier, which itself bypassed RoguePlanet, another Defender flaw the security researcher disclosed in June and Microsoft patched in July.
Naceri's zero-day exploits released this year also include LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend, which target Microsoft Defender, BitLocker, and other Windows components.
Microsoft initially responded with warnings of legal action against anyone engaging in "malicious activity causing real harm" to the company's customers, leading many in the infosec community to believe that Microsoft was directly threatening the security researcher.
While Microsoft has fixed some of the security flaws Naceri disclosed (such as ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma flaws), the other security issues still lack an official patch.
A Microsoft spokesperson was not immediately available to comment when BleepingComputer reached out about the BigDiskBuster denial-of-service zero-day.
References in this story
- GitHub - MSNightmare/BigDiskBuster: Windows Defender Update Denial of Service Vulnerability github.com Windows Defender Update Denial of Service Vulnerability - MSNightmare/BigDiskBuster
- Recently leaked Windows zero-days now exploited in attacks www.bleepingcomputer.com Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions.
- Abdelhamid Naceri (@MSNightmare2000) on X x.com Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background, https://t.co/5usGRBvPRn I think it can be better
- Abdelhamid Naceri (@MSNightmare2000) on X x.com Story time...
- Abdelhamid Naceri (@MSNightmare2000) on X x.com official termination landed in my mailbox dated 3rd of march 2025, I sued Microsoft for unfair termination in Cologne's labour court. (worst mistake of my life) In court, Microsoft refused to reveal any details about…
- All Windows versions impacted by new LPE zero-day vulnerability www.bleepingcomputer.com A security researcher has disclosed technical details for a Windows zero-day privilege elevation vulnerability and a public proof-of-concept (PoC) exploit that gives SYSTEM privileges under certain conditions.
- New Windows zero-day with public exploit lets you become an admin www.bleepingcomputer.com A security researcher has publicly disclosed an exploit for a new Windows zero-day local privilege elevation vulnerability that gives admin privileges in Windows 10, Windows 11, and Windows Server.
- Windows zero-day flaw giving admin rights gets unofficial patch, again www.bleepingcomputer.com A Windows local privilege escalation zero-day vulnerability that Microsoft has failed to fully address for several months now, allows users to gain administrative privileges in Windows 10, Windows 11, and Windows Server.
- INFINITE NIGHTMARE (@MSNightmare2000) on X x.com Microsoft has failed to properly patch ShieldBreak CVE-2026-69414 - https://t.co/dsbfA9dHtE ShieldCrash demonstrates a full bypass of the patch - https://t.co/nrGgk52947 Works with latest September 2026 patch
- New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges www.bleepingcomputer.com Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates.
- Security Update Guide - Microsoft Security Response Center msrc.microsoft.com
- Latest RoguePlanet news www.bleepingcomputer.com The latest news about RoguePlanet
- Microsoft patches RoguePlanet Defender zero-day vulnerability www.bleepingcomputer.com Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday.
- New Windows LegacyHive zero-day gives hackers admin privileges www.bleepingcomputer.com A security researcher using the "Nightmare Eclipse" handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems.
- Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit www.bleepingcomputer.com Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft, allowing attackers to gain SYSTEM or elevated administrator permissions.
- New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges www.bleepingcomputer.com A researcher known as "Nightmare Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity…
- Windows BitLocker zero-day gives access to protected drives, PoC released www.bleepingcomputer.com A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
- Windows BitLocker zero-day gives access to protected drives, PoC released www.bleepingcomputer.com A cybersecurity researcher has published proof-of-concept (PoC) exploits for two unpatched Microsoft Windows vulnerabilities named YellowKey and GreenPlasma, which are a BitLocker bypass and a privilege-escalation flaw.
- New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released www.bleepingcomputer.com A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched Windows systems.
- A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure www.microsoft.com
- Microsoft Security Response Center (@msftsecresponse) on X x.com Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical…



