New Windows Defender zero-day blocks Microsoft antivirus updates

In a worrying development, cybersecurity researcher Abdelhamid Naceri has released yet another zero-day exploit targeting Microsoft’s Windows Defender antivirus software. The new exploit, dubbed “BigDiskBuster”, blocks Windows Defender updates on all supported Windows versions, leaving users vulnerable to malware attacks.

Naceri, who claims to be a former Microsoft employee and has been involved in an ongoing dispute with the company over his alleged unfair termination, released BigDiskBuster as part of his efforts to expose vulnerabilities in Microsoft’s security software. The exploit works by running in the background, denying Windows Defender the ability to update its definitions or signatures.

This is not Naceri’s first zero-day exploit targeting Windows Defender. In April 2026, he released a similar exploit called “UnDefend”, which also blocked definition updates. Since then, he has released almost a dozen other exploits as part of his ongoing dispute with Microsoft, including ones that grant SYSTEM access and allow privilege escalation on various Windows versions.

Microsoft has responded to Naceri’s releases by warning users against engaging in “malicious activity causing real harm” to the company’s customers, leading some in the infosec community to believe that Microsoft is directly threatening Naceri. While Microsoft has patched some of the security flaws disclosed by Naceri, many others still lack an official fix.

The impact of BigDiskBuster on users is significant. With Windows Defender unable to update its definitions, users are left vulnerable to malware attacks and other cyber threats. This can lead to data breaches, system crashes, and even identity theft.

What’s concerning about this situation is that Naceri has been highlighting these vulnerabilities for months, yet Microsoft has failed to provide a comprehensive fix. The lack of patching raises questions about the effectiveness of Microsoft’s security measures and whether they are doing enough to protect their users from cyber threats.

In practical terms, this means that Windows users should be cautious when using BigDiskBuster or any other exploit targeting Windows Defender. While Naceri has released these exploits as proof-of-concept tools, they can still cause harm if not handled carefully. Users should exercise caution and consider alternative security solutions to protect their systems.

Ultimately, the situation highlights the ongoing cat-and-mouse game between cybersecurity researchers and software vendors. As researchers expose vulnerabilities in security software, vendors must respond quickly with patches and fixes to prevent users from being exploited.


Source: Bleeping Computer — 2026-09-22