Over the weekend, security researcher Abdelhamid Naceri, widely known in cybersecurity circles as "Nightmare Eclipse," unveiled a new exploit targeting Microsoft Defender, the built-in antivirus solution for Windows operating systems. This latest discovery, dubbed "BigDiskBuster," represents another significant zero-day vulnerability, capable of preventing Defender from receiving crucial updates. This development escalates an ongoing feud between Naceri and Microsoft, fueled by the researcher’s allegations of unfair termination by the tech giant.
BigDiskBuster’s functionality is designed to operate in the background, effectively halting the automatic download and installation of both platform and signature updates for Microsoft Defender. Naceri explicitly stated that this proof-of-concept exploit is similar in nature to a previously released zero-day, "UnDefend," which also allowed standard users to disrupt definition updates. The researcher claims that BigDiskBuster is effective across all currently supported Windows versions, though he acknowledges that the current proof-of-concept requires further refinement. "Made a funny tool, completely denies defender from updating so you’re stuck with your current version if the tool is running in the background," Naceri remarked on social media platform X, formerly Twitter. He further elaborated, "This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea."
The release of BigDiskBuster is part of a broader pattern of zero-day disclosures by Naceri, which began in earnest following his alleged termination by Microsoft in March 2025. Since April 2026, Naceri has been systematically releasing a series of exploits, many targeting Microsoft Defender, in what appears to be a public campaign to highlight security flaws within Microsoft’s products and to draw attention to his dispute with the company. This ongoing series of disclosures has seen nearly a dozen zero-day exploits made public, including significant vulnerabilities that grant elevated privileges.
A Pattern of Exploits and Escalating Tensions
The emergence of BigDiskBuster follows closely on the heels of another impactful zero-day exploit, "ShieldCrash," released by Naceri just two weeks prior. ShieldCrash, a vulnerability that grants SYSTEM access, was disclosed shortly after Microsoft’s monthly Patch Tuesday updates were rolled out, a timing that suggests a deliberate strategy by the researcher. According to Naceri, ShieldCrash bypasses another Defender privilege escalation flaw known as "ShieldBreak," which Microsoft had patched approximately a week before ShieldCrash’s disclosure. ShieldBreak itself was a fix for "RoguePlanet," another Defender zero-day vulnerability that Naceri had disclosed in June and which Microsoft subsequently patched in July.
This cascading effect, where one exploit bypasses a recently patched vulnerability, highlights the dynamic and often adversarial nature of cybersecurity research and vulnerability disclosure. The chain of events involving ShieldBreak and RoguePlanet demonstrates a persistent cat-and-mouse game between vulnerability researchers and software vendors, especially when disputes over disclosure or compensation arise.

Naceri’s portfolio of publicly disclosed zero-day exploits released this year is extensive and targets various critical components of the Windows operating system. Beyond BigDiskBuster and ShieldCrash, his disclosures include:
- LegacyHive: A zero-day exploit that grants hackers administrative access to Windows systems.
- BlueHammer: Another vulnerability affecting Windows.
- RedSun: A proof-of-concept exploit that grants system privileges within Microsoft Defender.
- YellowKey: A zero-day vulnerability affecting Windows BitLocker, enabling access to protected drives.
- GreenPlasma: Another exploit related to BitLocker access.
- MiniPlasma: A zero-day exploit that grants system access.
- UnDefend: The predecessor to BigDiskBuster, which allowed users to block Defender definition updates.
These exploits collectively target not only Microsoft Defender but also other integral Windows components like BitLocker, underscoring a broad spectrum of potential security weaknesses within the operating system.
Microsoft’s Response and the Broader Implications
Microsoft’s initial response to Naceri’s wave of disclosures was marked by a strong stance. The company issued a public statement emphasizing the importance of "coordinated vulnerability disclosure" and warned of potential legal action against individuals engaging in "malicious activity causing real harm" to its customers. This statement was widely interpreted within the cybersecurity community as a direct warning to Naceri, signaling Microsoft’s displeasure and intent to protect its user base and business interests.
Despite the public admonishments, Microsoft has, in fact, patched several of the vulnerabilities Naceri has disclosed. Notably, flaws like ShieldBreak, RoguePlanet, YellowKey, GreenPlasma, and MiniPlasma have received official patches from Microsoft, indicating that the company does investigate and address vulnerabilities brought to its attention, even when the disclosure method is contentious. However, a significant number of other reported security issues, including the recently revealed BigDiskBuster, appear to remain unaddressed as of the time of reporting.
The implications of Naceri’s BigDiskBuster exploit are particularly concerning. By preventing Microsoft Defender from updating its threat definitions, it leaves systems vulnerable to newly emerging malware, ransomware, and other cyber threats. Antivirus software relies heavily on up-to-date signature databases to detect and neutralize the latest malicious code. If these updates are blocked, even a robust antivirus program can become ineffective against contemporary cyberattacks. This creates a window of opportunity for attackers to compromise systems that are otherwise protected by Defender but are unable to receive critical security intelligence.
For organizations and individuals reliant on Windows Defender as their primary security solution, the ability of an attacker to disable update mechanisms poses a significant risk. It underscores the importance of a multi-layered security approach, which includes not only endpoint protection but also network security, user education, and timely patching of all software.

The Researcher’s Motivation and the Cybersecurity Landscape
Abdelhamid Naceri’s actions appear to be driven by a complex interplay of professional grievances and a desire to expose what he perceives as security shortcomings and unfair practices. His detailed documentation and public release of exploits, often accompanied by proof-of-concept code, suggest a methodical approach to his campaign. While some in the cybersecurity community may view his methods as disruptive, others see him as a whistleblower holding a major technology vendor accountable.
The ongoing dispute also raises broader questions about the ethics and practices of vulnerability disclosure. While bug bounty programs and coordinated disclosure policies are designed to incentivize researchers to report flaws responsibly, disputes can arise over compensation, recognition, and the interpretation of responsible disclosure timelines. Naceri’s case highlights the potential for such disputes to spill into the public domain, with significant consequences for both the vendor and its customers.
The cybersecurity industry has long grappled with the balance between rapid disclosure for public awareness and responsible disclosure that allows vendors adequate time to patch vulnerabilities. Researchers like Naceri, when faced with what they perceive as inadequate responses or unfair treatment, may resort to more aggressive disclosure tactics, such as releasing zero-day exploits. This can put users at immediate risk but also exert significant pressure on vendors to address critical security issues.
As of the time of this report, Microsoft had not provided an immediate comment regarding the BigDiskBuster zero-day denial-of-service exploit, leaving the security community and Windows users awaiting official clarification or a commitment to a patch. The situation remains fluid, with the potential for further disclosures or developments in Naceri’s campaign against Microsoft. The ongoing saga serves as a stark reminder of the constant vigilance required in the cybersecurity domain and the complex relationships that exist between those who discover vulnerabilities and those who are responsible for securing vast technological ecosystems. The ability to disable critical security updates, even temporarily, represents a potent weapon in the hands of malicious actors and a significant challenge for defenders.







