Researcher's latest Windows Defender flaw freezes signature updates

A security researcher known as Nightmare Eclipse has published a proof-of-concept exploit that prevents Microsoft Defender from receiving platform and signature updates on all supported Windows versions. The tool, named BigDiskBuster, must run continuously in the background to maintain the denial-of-service condition. This is part of an ongoing series of zero-day disclosures by the researcher following a dispute with Microsoft over an alleged unfair termination.
The BigDiskBuster tool requires continuous background execution to sustain its denial-of-service condition against Defender's update mechanisms. Naceri acknowledged the proof-of-concept remains somewhat unstable and needs refinement. This release follows a pattern of nearly a dozen disclosures since April 2026, all stemming from the researcher's dispute with Microsoft over their March 2025 termination.
Microsoft has patched several disclosed flaws, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, while others remain unaddressed. The company previously warned of legal action against malicious activity harming customers. BleepingComputer received no immediate comment from Microsoft regarding this latest disclosure.
Repeated disclosure of unpatched Defender flaws could leave enterprise and consumer systems vulnerable to malware exploiting outdated signatures. Organizations relying on Microsoft's built-in antivirus may face increased risk until patches arrive, while the researcher's ongoing campaign may pressure Microsoft to address disclosure disputes more transparently. The situation could also erode trust in Windows security defaults, prompting users to seek third-party protection.