Security researcher Abdelhamid Naceri, who also goes by Nightmare Eclipse, has published a new zero-day proof of concept targeting Microsoft Defender. Dubbed BigDiskBuster, the tool prevents Windows Defender from receiving platform and signature updates as long as it runs in the background, effectively freezing the antivirus at its current version.

Naceri describes BigDiskBuster as functionally similar to UnDefend, an earlier zero-day he released in April that let standard users (without admin rights) block definition updates. He says the new PoC works across all currently supported versions of Windows, though he cautions that the code is “a bit buggy” and needs rewriting.

Part of an Ongoing Dispute

BigDiskBuster is the latest in a long string of zero-day releases from Naceri, who says he has been targeting Microsoft since an alleged unfair termination in March 2025. Since April 2026, he has published nearly a dozen exploits affecting Defender, BitLocker, and other Windows components, including LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, RoguePlanet, ShieldBreak, and most recently ShieldCrash, a privilege escalation flaw that grants SYSTEM access and was released just weeks after Microsoft’s September Patch Tuesday.

According to Naceri, each new exploit has effectively superseded the last: ShieldCrash bypasses the ShieldBreak fix, which itself bypassed the earlier RoguePlanet flaw. Microsoft has patched several of the disclosed issues, including ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma, but a number of others, including UnDefend and now BigDiskBuster, remain unaddressed.

No Official Response Yet

Microsoft previously warned of potential legal action against anyone engaging in “malicious activity causing real harm” to its customers, a statement many in the security community interpreted as directed at Naceri. The company has not issued a statement specifically addressing BigDiskBuster.

Because the tool requires local execution to block updates, its practical risk is tied to systems where an attacker has already gained code execution or where a malicious background process can be planted. Even so, a working technique that can silently stall antivirus updates on any supported Windows build is a meaningful concern for defenders, particularly given Naceri’s track record of following up disclosed issues with functional bypasses. Organizations should monitor for unusual processes preventing Defender update checks and watch for official guidance from Microsoft.