A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience

Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame edge-to-edge photoreal editorial image of a darkened office workstation, a large monitor showing an abstract stalled progress bar in cool blue tones,
Share

Key points

  • Microsoft has publicly named six of the flaws (RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, MiniPlasma) as being released without warning, an unusually direct rebuke from the vendor.
  • The newest release, BigDiskBuster, stops Microsoft Defender from downloading definition and platform updates on every supported Windows version.
  • Researcher Abdelhamid Naceri, who also goes by Nightmare Eclipse, has published close to a dozen Windows zero-days since April 2026 in a dispute over what he says was an unfair firing by Microsoft in March 2025.
  • Microsoft has shipped patches for ShieldBreak, RoguePlanet, YellowKey, GreenPlasma and MiniPlasma. BigDiskBuster, UnDefend, ShieldCrash, LegacyHive, BlueHammer and RedSun still have no fix.
  • Microsoft has warned of legal action against anyone causing "real harm" to customers, wording widely read in the security community as aimed at Naceri.

The latest one is called BigDiskBuster. Run it in the background on a Windows machine and Microsoft Defender, the antivirus built into Windows, can no longer pull down updates. It stays frozen at whatever version it had when the tool started running.

Naceri, who first reported it over the weekend in a post covered by BleepingComputer, described the tool bluntly: "completely denies defender from updating so you're stuck with your current version." He said it behaves like an earlier zero-day of his called UnDefend, which let ordinary users block definition updates back in April. He also noted the proof-of-concept is still rough and needs rewriting.

A zero-day is a software flaw the maker did not know about before it went public. In this case the maker could read the proof-of-concept online like everyone else. What Microsoft did not get was the private heads-up that vendors normally receive before details go out.

Why is Microsoft this annoyed?

Because the company says the disclosures skipped the process it relies on to protect users. In a blog post from its Security Response Center, Microsoft said the details "were not shared with Microsoft prior to release, and the disclosures put our customers at unnecessary risk."

The post names six flaws directly: RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma and MiniPlasma. That is rare. Vendors usually keep researcher disputes private, so naming the bugs and framing them as reckless tells you how sour this has turned.

The industry norm is called Coordinated Vulnerability Disclosure, or CVD: a researcher finds a bug, tells the vendor, waits for a patch, then publishes. Naceri is not doing that. He says Microsoft fired him unfairly in March 2025, and the exploits are a very public form of pressure.

What actually works today and what is still broken?

Microsoft has issued patches for some of the flaws in the series. Others, including the new one, are still live.

Flaw Target Status
BigDiskBuster Defender updates Unpatched
ShieldCrash Defender (SYSTEM access) Unpatched
UnDefend Defender updates Unpatched
ShieldBreak Defender Patched
RoguePlanet Defender Patched (July)
YellowKey, GreenPlasma, MiniPlasma Windows components Patched

ShieldCrash is the one that should worry defenders most. It grants SYSTEM access, the highest level of control on a Windows machine. As we reported on 17 September, Naceri said it walks straight past Microsoft's patch for ShieldBreak, which itself bypassed RoguePlanet. Three rounds of patch-and-bypass on the same code path.

Should ordinary Windows users do anything?

Probably not much beyond the usual. BigDiskBuster has to already be running on your machine to work, meaning an attacker needs a foothold first. It's a tool for making a bad situation worse, not for breaking in from the outside.

Keep Windows Update on. If you rely on Defender alone, know that a determined attacker with local access can now freeze it in place until Microsoft ships a fix.

My read: the technical story is real but narrow. The bigger one is a vendor and a researcher openly at war, with the rest of us reading the exploit code in real time. Microsoft's legal warning has not slowed the releases. Watch whether the next Patch Tuesday closes BigDiskBuster and ShieldCrash, and whether anyone picks up Naceri's proof-of-concept code and uses it outside a lab.

© 2026 Threat Vectr