Skip to main content

Morning Overview

New zero-day bug can silently block Windows Defender’s virus updates

A researcher who calls himself Nightmare Eclipse published a free tool on September 19, 2026, that can quietly stop Windows Defender from installing its own virus-definition and platform updates, leaving the antivirus running but frozen on outdated protection. The tool, named BigDiskBuster, works on every supported version of Windows and has no patch. Microsoft had not issued a fix or a public comment as of the story’s publication.

The person behind the tool identifies himself as Abdelhamid Naceri, a former Microsoft employee who says the company mistreated him and revoked his ability to report vulnerabilities through normal channels. He has released close to a dozen zero-days targeting Defender since April 2026, and BigDiskBuster is the latest entry in a monthly cadence that has included tools named UnDefend, BlueHammer, RedSun, RoguePlanet, LegacyHive and ShieldBreak, each aimed at some part of the same antivirus platform.

How BigDiskBuster starves Defender of disk space

According to BleepingComputer’s report on the release and a technical writeup by The Hacker News, the tool watches the folders Defender uses for update staging and, the moment an update attempt begins, creates hidden temporary files sized to consume whatever free disk space remains. The update fails, the tool deletes its filler files, and it waits for Defender to try again. The same report says BigDiskBuster also opens a lock on MRT.exe, the Malicious Software Removal Tool, blocking Windows Update from replacing it. The practical result, visible to an affected machine as a generic installation error, is a security product that keeps running but never learns about new threats, a slow bleed rather than an obvious crash.

Naceri described his own creation bluntly in comments cited by BleepingComputer: it “completely denies defender from updating.” He has also acknowledged the tool is rough, telling The Hacker News it is “a bit buggy and needs some rewritting,” language that suggests a working proof-of-concept rather than a polished attack kit, though security researchers note that a crude tool can still be effective against a platform that has no defense against it at all.

A pattern going back to Naceri’s split with Microsoft

The dispute traces to Naceri’s departure from Microsoft’s security research relationship, which he has said happened without cause. The Register reports that Microsoft responded to his April 2026 disclosures by invoking its Digital Crimes Unit, language researchers read as a legal threat, before walking that back and clarifying it had “no intention to pursue action against individuals conducting or publishing security research.”

Some of Naceri’s earlier Defender flaws did get fixed, and one of them shows what happens when a similar bug goes unpatched for months. UnDefend, the tool BleepingComputer and other outlets say BigDiskBuster most closely resembles, was assigned CVE-2026-45498 and eventually patched in Microsoft Defender Antimalware Platform version 4.18.26040.7. The National Vulnerability Database entry for that flaw rates it 7.5 on the CVSS scale and describes it as a denial-of-service bug caused by uncontrolled resource consumption, the same underlying weakness class BigDiskBuster appears to exploit through disk space rather than memory or CPU.

The earlier bug was not a theoretical risk. Help Net Security reported that CVE-2026-45498 was confirmed exploited in the wild and added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog on May 20, 2026, which gave federal agencies until June 3 of that year to patch it or stop using the affected product. Whether BigDiskBuster follows the same arc, from proof-of-concept to real intrusions to an eventual patch, is the open question hanging over this disclosure.

No CVE, no patch, and limited options for now

Because BigDiskBuster has no assigned CVE and no vendor advisory, it sits outside the normal channels IT administrators use to track and prioritize fixes. BleepingComputer’s report notes Naceri claims the tool works across all currently supported Windows releases, which would put both consumer PCs and managed enterprise fleets in the same boat until Microsoft ships a fix.

Security teams watching Naceri’s monthly release cadence have one practical lever in the meantime: freeing up disk space and monitoring for update failures does not close the underlying flaw, but it can make the specific disk-filling technique harder to sustain. Endpoint tools that alert on repeated update-installation errors, rather than assuming Defender is simply slow to sync, are one of the few detection paths available while the bug remains unpatched.

The bigger unresolved issue is coordination. Naceri has said publicly that he no longer trusts Microsoft’s bug-bounty and disclosure process, and the company’s own mixed signals, first threatening legal action, then disavowing that threat, have not repaired the relationship. Every month that standoff continues, another Defender component becomes a public target, and each new release lands on defenders’ desks with no advance warning and no fix ready to deploy.

None of that closes the gap BigDiskBuster opened. It leaves a stopgap, not a solution, and the question Microsoft has not yet answered publicly: when, and whether, a patch for BigDiskBuster is coming.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview