Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zero-Day Tool Blocks Microsoft Defender Updates

Zero-Day Tool Blocks Microsoft Defender Updates

Posted on September 22, 2026 By CWS

An unpatched zero-day tool named BigDiskBuster, which prevents Microsoft Defender from carrying out platform and signature updates by consuming all available disk space, was made public on GitHub on September 19. The tool, created by former Microsoft security researcher Abdelhamid Naceri, has neither a patch nor a CVE, and Microsoft has yet to release an advisory regarding this vulnerability.

Background on BigDiskBuster

Naceri, who was previously part of Microsoft’s Security Response Center until his dismissal in 2024, has been releasing exploits without coordination with the company since April. His prior tools have been involved in live attacks before Microsoft issued patches, with his creations being listed in CISA’s Known Exploited Vulnerabilities catalog.

The newly disclosed BigDiskBuster operates by monitoring the C: drive for new directories under Defender’s update paths. When an update is initiated, the tool generates a hidden temporary file to occupy the entire available disk space, causing the update process to fail. Once the update attempt is unsuccessful, the tool deletes the file and awaits the next update effort. It also obstructs Windows Update by holding a handle on MRT.exe, the Windows Malicious Software Removal Tool.

Comparing BigDiskBuster and Prior Tools

Naceri likens BigDiskBuster to a previous tool, UnDefend, which he released in April. While both tools aim to disrupt Defender updates, UnDefend did so through uncontrolled resource consumption, whereas BigDiskBuster fills the disk to impede directory growth. Microsoft addressed the UnDefend flaw in May with a patch identified as CVE-2026-45498.

Despite the differences in technique, it remains uncertain whether the May patch also mitigates BigDiskBuster’s approach. As of now, no independent researchers have verified Naceri’s claims about the tool’s functionality.

Recommendations for Security Administrators

Currently, no official patch or vendor workaround exists for BigDiskBuster, posing an ongoing risk to systems running Microsoft Defender. Administrators are advised to ensure that Defender’s signatures and platform versions remain up-to-date. This can be verified via Windows Security under the Virus & threat protection section or through PowerShell commands like Get-MpComputerStatus.

To detect potential misuse of BigDiskBuster, administrators should monitor for repeated Defender update failures, consistently low disk space on system volumes, and the presence of large hidden files in temporary directories. Employing security measures such as Windows Defender Application Control (WDAC) or AppLocker to restrict the execution of unknown binaries can also help mitigate the risk of attack.

As the cybersecurity community awaits a response from Microsoft, vigilance and proactive security practices remain essential to safeguard systems from this zero-day threat.

The Hacker News Tags:Abdelhamid Naceri, BigDiskBuster, Cybersecurity, endpoint security, GitHub, IT security, Microsoft Defender, network security, security patches, software vulnerabilities, Vulnerability, Windows security, zero-day

Post navigation

Previous Post: Veeam Agent Vulnerability Exploited for SYSTEM Privileges
Next Post: Critical Flaw in OpenShift Allows Malicious Releases

Related Posts

China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom China-linked Salt Typhoon Exploits Critical Cisco Vulnerability to Target Canadian Telecom The Hacker News
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks The Hacker News
GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites The Hacker News
Cybercrime Groups Exploit Vishing for SaaS Attacks Cybercrime Groups Exploit Vishing for SaaS Attacks The Hacker News
5 BCDR Essentials for Effective Ransomware Defense 5 BCDR Essentials for Effective Ransomware Defense The Hacker News
VOID#GEIST Malware Campaign Unveils Advanced RAT Delivery VOID#GEIST Malware Campaign Unveils Advanced RAT Delivery The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark