Vulnerability
NightmareEclipse Zero-Day Exploits Leave Microsoft Defender Vulnerable
A critical zero-day vulnerability dubbed 'BigDiskBuster' has been discovered, preventing Microsoft Defender from updating and leaving systems exposed to evolving threats.
Dissecting the BigDiskBuster Vulnerability Security researchers have uncovered a new zero-day vulnerability, named 'BigDiskBuster,' which specifically targets the update mechanism of Microsoft Defender. By exploiting this flaw, the threat actor NightmareEclipse can effectively freeze the antivirus engine's update cycle. Consequently, while the service appears to be running, it remains trapped in a legacy state, unable to receive the latest threat intelligence signatures. This renders the protected system blind to modern malware variants, creating a 'silent failure' state that is notoriously difficult for standard monitoring tools to detect. This vulnerability is particularly dangerous because it does not crash the system, but rather slowly erodes its defensive capabilities. ## Proactive Defense and Patch Hygiene To mitigate the risks associated with this zero-day, organizations should take immediate defensive actions: 1. Monitor Antivirus Health: IT and security teams must implement monitoring alerts that check for the timestamp of the latest signature update, not just the service status. If updates fail for more than 24 hours, an automated alert must be triggered. 2. Defense in Depth: Do not rely solely on Microsoft Defender. Deploy secondary endpoint security tools or EDR solutions that operate independently of the primary OS antivirus. This creates a redundant layer of protection. 3. Patching Strategy: Maintain an aggressive schedule for operating system updates. Even when an application-specific patch isn't available, keeping the overall OS environment up to date can often block the secondary payloads that threat actors attempt to deliver after disabling your primary defenses.
แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 18:36:00 +0200 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: The Register - Security
เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 18:36:00 +0200
บทความต้นฉบับ: https://www.theregister.com/security/2026/09/22/nightmareeclipses-latest-zero-day-leaves-microsoft-defender-stuck-in-the-past/5298320
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
