Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Editor's note: Information on BigDiskBuster is based solely on the primary source BleepingComputer, which reports direct statements from researcher Abdelhamid Naceri. No independent verification of the tool's operation is available. The exact technical mechanism has not been disclosed beyond the researcher's description.
On September 20, 2026, Abdelhamid Naceri, known as Nightmare Eclipse, publicly released BigDiskBuster, a tool that — according to the researcher — prevents Microsoft Windows Defender from receiving platform and signature updates when running in the background. The release marks an escalation in the ongoing dispute between Naceri and Microsoft, which began in March 2025 over an alleged wrongful termination.
- According to Naceri, BigDiskBuster blocks Windows Defender platform and signature updates when running in the background.
- The researcher claims the tool works on all supported Windows versions, but describes the PoC as "a bit buggy" and in need of rewriting.
- No independent verification of BigDiskBuster's functionality is available; the exact technical mechanism has not been disclosed.
- No CVE has been assigned and no patch is in development for BigDiskBuster as of September 20, 2026.
- Microsoft has not issued immediate comment on the tool.
What the Researcher Claims
Naceri's statements, reported by BleepingComputer as the sole direct primary source, constitute the only available evidence on BigDiskBuster's operation. The researcher described the tool as follows: "Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background".
Naceri further specified that BigDiskBuster is "similar to UnDefend", a previous zero-day released in April 2026 that, according to the researcher, allowed blocking definition updates. He added: "This proof of concept is similar to UnDefend, it prevents windows defender from performing platform/signature updates. Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting but you get the idea".
"Seems to work on all supported windows versions but PoC is a bit buggy and needs some rewritting" — Abdelhamid Naceri (Nightmare Eclipse), via BleepingComputer, September 20, 2026
Context: The Exploit Series in the Dispute with Microsoft
BigDiskBuster fits into a sequence of releases that has characterized the dispute between Naceri and Microsoft. Two weeks earlier, on September 9, 2026, the researcher released ShieldCrash, a bypass of ShieldBreak (CVE-2026-69414). ShieldBreak was itself a bypass of the patch for RoguePlanet (CVE-2026-50656), a race condition in the Microsoft Malware Protection Engine.
Microsoft assigned CVE-2026-69414 to ShieldBreak on August 14, 2026, with a CVSS score of 7.8 and an "Exploitation More Likely" status. The patch is available in Malware Protection Engine version 1.1.26080.3. The NVD record for this CVE was published on September 16, 2026.
Since April 2026, Naceri has released nearly a dozen zero-days in his dispute with Microsoft. The primary source does not specify whether BigDiskBuster represents a technical continuation of the same attack surface or a tool with an independent mechanism.
What Changes
The distinction Naceri draws between BigDiskBuster and previous exploits lies in the target: while ShieldBreak and ShieldCrash targeted privilege escalation, BigDiskBuster — again according to the researcher — targets update blocking. The primary source does not specify the technical mechanism that enables this blocking, nor whether the tool requires specific privileges to execute.
The researcher himself highlighted limitations of the PoC, describing it as unstable. This characterization contrasts with previous statements on ShieldBreak, where Naceri claimed a "100% success rate" on Windows 11 25H2 and Windows Server 2025 — according to Tech Insider.
Frequently Asked Questions
Has the researcher verified BigDiskBuster on all Windows versions?
According to BleepingComputer, Naceri claims the tool "seems to work on all supported Windows versions," but adds that the PoC is "a bit buggy." No independent third-party verification or systematic testing across all versions exists. The primary source does not specify which versions the researcher actually tested.
Does the ShieldBreak patch also protect against BigDiskBuster?
It cannot be determined. As of September 20, 2026, no CVE has been assigned for BigDiskBuster and no patch in development has been announced by Microsoft. The primary source provides no information on the technical relationship between the two vulnerabilities.
Has Microsoft responded to the release?
No. According to BleepingComputer, Microsoft has not issued immediate comment on BigDiskBuster at the time of the news publication.
When did the dispute between Naceri and Microsoft begin?
The dispute originated in March 2025, when Naceri alleged wrongful termination by Microsoft. Since then, the researcher has released nearly a dozen zero-days.
Conclusion
As of September 20, 2026, BigDiskBuster remains an independently unverified tool whose technical mechanism has not been disclosed beyond its author's statements. The public availability of the PoC, combined with the instability acknowledged by Naceri himself, makes its real-world operational impact uncertain. Microsoft has not yet responded to the release. The episode confirms the persistence of the dispute between the researcher and the vendor, but the lack of independent technical evidence warrants caution in evaluating claims about the tool's functionality.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
- https://arcticwolf.com/resources/blog/cve-2026-50656-rogueplanet-shieldbreak/
- https://tech-insider.org/microsoft-defender-shieldbreak-zero-day-2026/
- https://nvd.nist.gov/vuln/detail/CVE-2026-50656
- https://nvd.nist.gov/vuln/detail/CVE-2026-69414
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69414
- https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
- https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit
- https://blog.netmanageit.com/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.