MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

Researcher's latest Windows Defender flaw freezes signature updates

Image via BleepingComputer
Image via BleepingComputer

A security researcher known as Nightmare Eclipse has published a proof-of-concept exploit that prevents Microsoft Defender from receiving platform and signature updates on all supported Windows versions. The tool, named BigDiskBuster, must run continuously in the background to maintain the denial-of-service condition. This is part of an ongoing series of zero-day disclosures by the researcher following a dispute with Microsoft over an alleged unfair termination.

Expanded Detail

The BigDiskBuster tool requires continuous background execution to sustain its denial-of-service condition against Defender's update mechanisms. Naceri acknowledged the proof-of-concept remains somewhat unstable and needs refinement. This release follows a pattern of nearly a dozen disclosures since April 2026, all stemming from the researcher's dispute with Microsoft over their March 2025 termination.

Microsoft has patched several disclosed flaws, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, while others remain unaddressed. The company previously warned of legal action against malicious activity harming customers. BleepingComputer received no immediate comment from Microsoft regarding this latest disclosure.

Context

Repeated disclosure of unpatched Defender flaws could leave enterprise and consumer systems vulnerable to malware exploiting outdated signatures. Organizations relying on Microsoft's built-in antivirus may face increased risk until patches arrive, while the researcher's ongoing campaign may pressure Microsoft to address disclosure disputes more transparently. The situation could also erode trust in Windows security defaults, prompting users to seek third-party protection.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Microsoft patches false antivirus shutdown warnings triggered by recent updates · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “New Windows Defender zero-day blocks Microsoft antivirus updates.” Browse more stories.