Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Defender update-blocking disk exhaustion security flaw

Vulnerability
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

BigDiskBuster exposes a Microsoft Defender flaw that can block platform and signature updates by exhausting disk space, leaving detection content stale on affected Windows systems. The zero-day proof-of-concept was published on GitHub on September 19, and there is no patch, CVE, or Microsoft advisory yet. The tool also targets MRT.exe, and the reported behavior appears to affect supported Windows versions.

Related Happenings

Microsoft Defender update-blocking zero-day security flaw

Vulnerability
H score7 First: 22.09.2026 12:55 Last: 22.09.2026 12:55 Sources 1

About this happening: A Microsoft Defender zero-day named BigDiskBuster can block platform/signature updates on supported Windows versions, freezing antivirus updates while it runs in t...

Microsoft Defender Antivirus false 'turned off' alerts after latest updates

Security Tool/Service
H score11 First: 31.08.2026 11:29 Last: 31.08.2026 11:29 Sources 1

About this happening: Microsoft Defender Antivirus is showing false 'turned off' alerts after the latest updates, creating confusion on supported Windows client and server systems even though p...

Latest development: 18.09.2026 15:16

Microsoft fixed the Defender Antivirus false-status alert issue in Microsoft Defender Antivirus update version 4.18.26080.4, released on September 17. The update addresses erroneous Windows Security app notifications that said "Microsoft Defender Antivirus is turned off" even though protection remained active, across supported Windows client and server versions including Windows 11 26H1 and Windows Server 2025.

Microsoft Defender signature update fixes scan-crash bug on Windows 10 and Windows 11

Security Tool/Service
H score11 First: 19.08.2026 14:14 Last: 19.08.2026 14:14 Sources 1

About this happening: Microsoft Defender now has a fix for a crash bug that broke scans on some Windows 10 and Windows 11 systems, restoring malware protection after a recent security updat...

Microsoft Defender BlueHammer (CVE-2026-33825) ransomware exploitation wave

Exploitation Wave
H score41 First: 30.06.2026 11:53 Last: 30.06.2026 11:53 Sources 1

About this happening: CISA has flagged BlueHammer (CVE-2026-33825) as exploited in ransomware campaigns, expanding the risk to Windows devices exposed to privilege escalation. The flaw in *...

Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)

Vulnerability
H score32 First: 17.06.2026 11:32 Last: 17.06.2026 11:32 Sources 1

About this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...

Timeline

  1. 22.09.2026 19:14 2 articles · 2h ago

    BigDiskBuster proof-of-concept appears on GitHub

    Initial Disclosure

    BigDiskBuster, a zero-day proof-of-concept attributed to Abdelhamid Naceri, watches Defender update paths on C:\\ and creates a hidden temporary file sized to fill all remaining free space when Microsoft Defender begins downloading a platform or definition update, causing the update to fail while Defender continues running; the tool also opens a handle on MRT.exe, the Windows Malicious Software Removal Tool.

    Show sources
  2. 22.09.2026 19:14 1 articles · 2h ago

    BigDiskBuster leaves Microsoft Defender detection content stale

    Victim Impact Update

    The disk-filling technique can leave Microsoft Defender's detection content stale, and the report says no patch or vendor workaround exists for BigDiskBuster. Naceri says the tool is similar to UnDefend, a Defender denial-of-service flaw disclosed in April and patched by Microsoft in May as CVE-2026-45498 in Antimalware Platform version 4.18.26040.7, but the article says it is not established that the May fix covers the new method; administrators are advised to check Defender versions, monitor repeated update failures, sustained low disk space, and hidden files, and restrict unknown binaries with WDAC or AppLocker.

    Show sources