Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 8 sources · 8 days · First seen · Last updated
Microsoft Defender zero-day exploit developments
Overview
Security researcher Abdelhamid Naceri, a former Microsoft employee, released a proof-of-concept exploit called ‘BigDiskBuster’. The tool functions as a denial-of-service attack that prevents Microsoft Defender from completing platform and signature updates by consuming available disk space. Naceri, who has released several zero-day exploits targeting Windows since April 2026, released the tool following a legal dispute with Microsoft regarding his termination.
Subsequent reports identified additional vulnerabilities affecting Microsoft security software. In addition to BigDiskBuster, a vulnerability known as ‘RedSun’ was disclosed, which targets the Microsoft Malware Protection Engine. This flaw allows attackers to overwrite files with SYSTEM-level privileges and execute arbitrary code. Although patches for RedSun were released in May 2026, the public availability of exploit code has increased the risk to users.
Entities
Abdelhamid Naceri · Microsoft · BigDiskBuster · CISA · Microsoft Malware Protection Engine
Timeline
-
[TECHNOLOGY] 2 sourcesMicrosoft Defender targeted by new zero-day exploits
New zero-day exploits, including BigDiskBuster and RedSun, target Microsoft Defender to disable updates or gain SYSTEM-level privileges on Windows systems.
-
[TECHNOLOGY] 6 sourcesAbdelhamid Naceri releases BigDiskBuster exploit targeting Microsoft Defender
Researcher Abdelhamid Naceri, known as Nightmare Eclipse, released ‘BigDiskBuster’, a new exploit that prevents Microsoft Defender from performing critical security updates on Windows.
Sources
aifen.fr · cybernoz.com · generation-nt.com · it-connect.fr · que.com · scan.netsecurity.ne.jp · softzone.es · techjuice.pk