Ethical Hacking News
A new zero-day threat has emerged in the Windows ecosystem, with researcher Swati Khandelwal releasing a proof-of-concept tool called BigDiskBuster that can block Microsoft Defender updates by filling all available disk space. With no patch or vendor workaround available, administrators are advised to monitor for repeated Defender update failures and take steps to limit an attacker's ability to run the tool. This article provides a detailed analysis of the threat and its implications for users of Windows operating systems.
Swati Khandelwal, a researcher, released BigDiskBuster, a zero-day proof-of-concept tool that blocks Microsoft Defender updates. The tool fills all available disk space to prevent update installation and has no patch, CVE, or Microsoft advisory. The tool has significant implications for Windows users relying on Microsoft Defender for security. Admins should monitor for repeated Defender update failures, low disk space, and large hidden files to detect the technique. Restricting unknown binaries through WDAC or AppLocker can limit an attacker's ability to run the tool. Abdelhamid Naceri, the author, has a history of releasing exploits without coordination with Microsoft. The release highlights the need for ongoing vigilance, collaboration, and transparency in the cybersecurity community.
Swati Khandelwal, a researcher and former Microsoft security researcher, has made waves in the cybersecurity community with the release of BigDiskBuster, a zero-day proof-of-concept (PoC) tool that can block Microsoft Defender updates by filling all available disk space. The tool, which has no patch, no CVE, and no Microsoft advisory, was published on GitHub on September 19, 2026, and has already sent shockwaves through the security community.
The BigDiskBuster tool works by watching the C:\ drive for new directories under Defender's update paths and creating a hidden temporary file sized to fill all remaining free space, thereby preventing the update from being installed. Once the update fails and Defender removes its staging directory, the tool deletes the file and waits for the next attempt. It also opens a handle on MRT.exe, the Windows Malicious Software Removal Tool, in a way that would block Windows Update from replacing it.
The emergence of BigDiskBuster has significant implications for users of Windows operating systems, particularly those who rely on Microsoft Defender for security. With no patch or vendor workaround available, administrators are advised to monitor for repeated Defender update failures, sustained low disk space on the system volume, and large hidden files in temporary directories to detect the technique. Restricting execution of unknown binaries through WDAC or AppLocker would also limit an attacker's ability to run the tool.
The author of BigDiskBuster, Abdelhamid Naceri, has a history of releasing exploits without coordinating with Microsoft, having been dismissed from the company's Security Response Center in 2024. His previous tools, BlueHammer, RedSun, and UnDefend, were all exploited in live intrusions before Microsoft patched them and CISA added them to its Known Exploited Vulnerabilities catalog.
Naceri's disclosure of BigDiskBuster follows a pattern of releasing exploits and vulnerabilities without coordination with Microsoft, highlighting the challenges faced by the company in keeping pace with the rapidly evolving threat landscape. The release of BigDiskBuster underscores the need for ongoing vigilance and collaboration between security researchers, vendors, and users to stay ahead of emerging threats.
The cybersecurity community is watching the situation closely, with many experts calling for greater transparency and collaboration between security researchers and vendors. The release of BigDiskBuster serves as a reminder of the importance of staying informed and up-to-date on the latest security threats and vulnerabilities, and the need for effective countermeasures to protect against them.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Shadow-of-BigDiskBuster-A-Zero-Day-Threat-Lurking-in-the-Windows-Ecosystem-ehn.shtml
https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html
Published: Tue Sep 22 13:29:39 2026 by llama3.2 3B Q4_K_M