"Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background," security researcher Abdelhamid Naceri — who also goes by the handle Nightmare Eclipse — wrote when he released a new proof-of-concept that blocks Microsoft Defender updates.
BigDiskBuster: what the new zero-day does
Over the weekend Naceri published a tool he named BigDiskBuster that he said prevents Microsoft Defender from performing signature and platform updates. According to the researcher, the PoC (proof-of-concept) allows standard users to block definition updates and must be running in the background to continue denying Microsoft Defender updates. Naceri described BigDiskBuster as "completely denies defender from updating" and said the PoC "needs some rewritting but you get the idea."
Technique and reach: how BigDiskBuster behaves
Naceri wrote that BigDiskBuster is similar to an earlier project he referenced as UnDefend, and that it operates as a denial-of-service against Defender's update mechanism. He also stated the tool "seems to work on all supported windows versions," implying broad coverage across current Windows releases. The researcher emphasized that the PoC is not final — calling it "a bit buggy" — and that it must remain active in the background to prevent Defender from updating.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWhere BigDiskBuster sits in a string of disclosures
BigDiskBuster is the latest in a sequence of Microsoft Defender flaws and PoCs Naceri has released. Two weeks earlier he published a zero-day called ShieldCrash that he said granted SYSTEM access; ShieldCrash followed a week-earlier flaw that bypassed RoguePlanet, a vulnerability Naceri disclosed in June and that Microsoft patched in July. The researcher has also disclosed other flaws that Microsoft has fixed — specifically ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma — while, he says, other issues remain without an official patch.
The releases are tied, per the source material, to an ongoing dispute between Naceri and Microsoft over "their alleged unfair termination in March 2025." The same reporting notes that Naceri said the releases were part of that dispute.
Microsoft response and current patch status
BleepingComputer reached out to Microsoft about the BigDiskBuster denial-of-service zero-day but a Microsoft spokesperson was not immediately available to comment. The reporting also states plainly that Microsoft "was directly threatening the security researcher," though no further details or quotes from Microsoft appear in the source material provided.
According to the disclosures cited, some of the flaws Naceri reported have been fixed by Microsoft — the list given includes ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma. Other security issues disclosed by Naceri, including BigDiskBuster at the time of reporting, "still lack an official patch."
What this means for security teams, enterprises, and end users
- Security teams and technologists: they will be watching for active processes that can prevent Defender updates, since Naceri says BigDiskBuster must run in the background to be effective. The existence of multiple related disclosures — some patched, some not — suggests teams will need to track which specific flaws have official fixes and which remain unpatched.
- Enterprises and procurement leaders: organizations that rely on Microsoft Defender for endpoint protection may need to confirm update status across fleets, because BigDiskBuster, as described, can leave systems "stuck with" their current Defender version while it runs.
- End users: per Naceri's description, users on affected systems could find Defender unable to update while the PoC is active, effectively preventing signature or platform updates until the blocking process stops.
The matter is straightforward in one sense: a publicly released Proof-of-Concept that denies antivirus updates raises operational and security concerns for any environment that depends on timely Defender signature and platform refreshes. The factual record from the source shows a patch history that is mixed — some flaws are fixed, others remain — and a researcher publicly tied to an employment dispute who continues to publish exploits. BleepingComputer's outreach to Microsoft on BigDiskBuster had not produced an immediate response at the time of reporting.




