# Microsoft Defender zero-day exploit developments

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-defender-zero-day-exploit-developments
> Updated: 2026-09-30T22:02:22.000Z. Sources: 8. Developments: 2.

Security researcher Abdelhamid Naceri, a former Microsoft employee, released a proof-of-concept exploit called ‘BigDiskBuster’. The tool functions as a denial-of-service attack that prevents Microsoft Defender from completing platform and signature updates by consuming available disk space. Naceri, who has released several zero-day exploits targeting Windows since April 2026, released the tool following a legal dispute with Microsoft regarding his termination.

Subsequent reports identified additional vulnerabilities affecting Microsoft security software. In addition to BigDiskBuster, a vulnerability known as ‘RedSun’ was disclosed, which targets the Microsoft Malware Protection Engine. This flaw allows attackers to overwrite files with SYSTEM-level privileges and execute arbitrary code. Although patches for RedSun were released in May 2026, the public availability of exploit code has increased the risk to users.

## Timeline

### 2026-09-30: Microsoft Defender targeted by new zero-day exploits

New zero-day exploits, including BigDiskBuster and RedSun, target Microsoft Defender to disable updates or gain SYSTEM-level privileges on Windows systems.

2 sources. https://clstr.news/cluster/microsoft-defender-targeted-by-new-zero-day-exploits

### 2026-09-23: Abdelhamid Naceri releases BigDiskBuster exploit targeting Microsoft Defender

Researcher Abdelhamid Naceri, known as Nightmare Eclipse, released ‘BigDiskBuster’, a new exploit that prevents Microsoft Defender from performing critical security updates on Windows.

6 sources. https://clstr.news/cluster/abdelhamid-naceri-releases-bigdiskbuster-exploit-targeting-microsoft-defender

---
Cite as: Microsoft Defender zero-day exploit developments. CLSTR, https://clstr.news/situations/microsoft-defender-zero-day-exploit-developments
