‘BigDiskBuster’ Leaves Microsoft Defender Running While Blocking Updates
darkreading.com Oct 7, 2026

‘BigDiskBuster’ Leaves Microsoft Defender Running While Blocking Updates

AI-summarised brief · reviewed before publication

Researchers from LevelBlue demonstrated a proof‑of‑concept attack called “BigDiskBuster” that blocks Windows Defender from receiving updates without exploiting a vulnerability. The technique monitors the C: drive for Defender update activity and, when an update starts, creates a hidden file that claims all free disk space. This causes the update to fail, after which Defender cleans the staging area and the process repeats. Defender’s real‑time protection remains active, creating a silent detection gap while the system stays out of date. The PoC was originally published by former Microsoft employee Abdelhamid Naceri (MSNightmare) on GitHub before removal.

💡 Why It Matters

  • · The method exposes a subtle weakness in Microsoft’s update mechanism, allowing attackers to keep systems unpatched while normal protection appears intact.
  • · This could enable prolonged exploitation of known vulnerabilities.