#windowsdefender
Abdelhamid Naceri, known as Nightmare Eclipse, publicly revealed his identity and released BigDiskBuster, a proof-of-concept exploit that disrupts Windows Defender updates on supported Windows versions. #BigDiskBuster #WindowsDefender #Germany
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, also known as Nightmare Eclipse, has publicly revealed his identity and released BigDiskBuster, a new proof-of-concept exploit that interferes with Windows Defender platform and signature updates. He says the tool works on all supported Windows versions, though it remains buggy, and he also recounted a bitter dispute with Microsoft...
www.hendryadrian.com
September 22, 2026 at 5:00 PM
📢 Windows Defender : nouveau zero-day BigDiskBuster bloque les mises à jour antivirus

📰 Source : BleepingComputer — Date : 22 septembre 2026 Le chercheur en sécurité Abdelhamid Naceri (alias Nightmare Eclipse) a publié…

🟡 vérification factuelle moyenne
#BigDiskBuster #WindowsDefender #Cyberveille
Windows Defender : nouveau zero-day BigDiskBuster bloque les mises à jour antivirus
📰 Source : BleepingComputer — Date : 22 septembre 2026 Le chercheur en sécurité Abdelhamid Naceri (alias Nightmare Eclipse) a publié un nouveau proof-of-concept (PoC) zero-day nommé BigDiskBuster, ciblant Microsoft Defender.
cyberveille.ch
September 22, 2026 at 12:30 PM
fzf君がWindowsDefenderにブロックされるようになってしまいストレス
September 17, 2026 at 3:09 PM
A new skeleton proof-of-concept demonstrates an arbitrary file read as SYSTEM on fully updated Windows systems, highlighting recurring flaws in Microsoft's patching process. #WindowsDefender #Security
MSNightmare drops ShieldCrash zero-day after Windows 11 patch
A new skeleton proof-of-concept demonstrates an arbitrary file read as SYSTEM on fully updated Windows systems, highlighting recurring flaws in Microsoft's patching process.
www.neowin.net
September 10, 2026 at 10:44 AM
A Windows Defender 0day has public PoC exploit code. ShieldCrash reads files as SYSTEM on all supported Windows versions.

#Windows"/hashtag/WindowsDefender" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#WindowsDefender #0day #CVE #ShieldCrash #CyberSecurity #Windows #PoC #Infosec
ShieldCrash: Windows Defender 0day With Public PoC Exploit
TL;DR A researcher published ShieldCrash, a Windows Defender 0day that bypasses Microsoft's patch for the ShieldBreak vulnerability (CVE-2026-6941). Both the vulnerability details and proof-of-concept exploit code are now public. The flaw reads arbitrary files as SYSTEM on all supported Windows versions. Why This Windows Defender 0day Matters The researcher, known as MSNightmare, released full details and working code on GitHub. Public exploit code lowers the bar for attackers.
securityonline.info
September 9, 2026 at 12:35 AM
Independent tests say #WindowsDefender is now as good as paid #antivirus

www.makeuseof.com/independent-...
Independent tests say Windows Defender is now as good as paid antivirus
Paying no longer buys better basic malware protection
www.makeuseof.com
September 3, 2026 at 1:29 PM
課金が存在するセキュリティソフトを導入しました。
一応信頼性・安全性がAIからの評価が「まずます」というもの。
直感的にWindowsDefenderでは限界がある「気がした」ので。
環境の合理化も行ってくれるのでこれまでも使っていたものの
課金版です。
これを使っている時に変なウィルスにかかった事はなかったので
それなりに信頼しています。
September 1, 2026 at 7:47 PM
📢 BTR Reforged : le driver de remédiation Windows Defender transformé en primitive noyau offensive

Cet article présente la première rétro-ingénierie complète du driver BTR.sys (Windows Defender Boot-Time Removal), un composant…

🟢 vérification factuelle haute
#WindowsDefender #BTRSys #Cyberveille
BTR Reforged : le driver de remédiation Windows Defender transformé en primitive noyau offensive
Cet article présente la première rétro-ingénierie complète du driver BTR.sys (Windows Defender Boot-Time Removal), un composant légitime signé Microsoft embarqué dans MpEngine.dll. L'analyse a débuté lors d'une investigation de réponse à incident où le driver avait été initialement confondu avec un artefact malveillant en raison de ses caractéristiques inhabituelles.
cyberveille.ch
August 22, 2026 at 6:30 PM
Reverse engineering of Windows Defender BTR.sys shows its encrypted boot-time transaction format can be abused for arbitrary file and registry operations from Ring 0, enabling EDR bypass and Defender neutralization. #BTRsys #WindowsDefender #Ring0
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
This research reverse engineers Windows Defender’s BTR.sys boot-time remediation driver and shows how its encrypted transaction format can be abused to perform arbitrary file and registry operations from Ring 0. The paper also introduces BTR_CLI, demonstrates EDR/AV bypass and boot-time neutralization against Microsoft Defender, and highlights the defensive implications of a signed built-in LOLDriver. #BTR.sys #BTR_CLI #MicrosoftDefender #MsMpEng.exe #WdFilter.sys #WdBoot.sys #WdNisDrv.sys #Mimikatz #mimidrv.sys #MSRC
www.hendryadrian.com
August 20, 2026 at 2:00 PM
📰 Microsoft Memperbaiki Bug yang Menyebabkan Windows Defender Crash

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/20/microsoft-perbaiki-windows-defender-crash-0xc0000005/

#ant
iv#antivirusr#cybersecuritya#malwareo#microsoftr#securityUpdateo#windows10o#windows11o#windowsDefender
August 20, 2026 at 11:09 AM
~Spiderlabs~
PoC abuses Cloud Files, Object Manager, and Defender APIs to achieve SYSTEM via phoneinfo.dll hijacking.
-
IOCs: C:\Windows\System32\phoneinfo[.]dll, \pipe\SHIELDBREAK, ShieldBreak[.]exe
-
#LPE #ThreatIntel #WindowsDefender
ShieldBreak Windows Defender LPE PoC
www.levelblue.com
August 19, 2026 at 4:13 PM
Microsoft fixed a Windows Defender bug that caused crashes and 0xc0000005 errors on some Windows 10 and 11 systems after a security update. The fix is in signature update 1.457.236.0 or later. #WindowsDefender #Microsoft #Windows11
Microsoft fixes known issue causing Windows Defender crashes
Microsoft has fixed a bug in Windows Defender that caused access violation errors and service crashes after a recent security update on some Windows 10 and Windows 11 systems. The issue triggered “Threat service has stopped. Restart it now” messages, and Microsoft says the correction is included in Defender signature update version 1.457.236.0 or later. #WindowsDefender #MicrosoftDefender
www.hendryadrian.com
August 19, 2026 at 4:00 PM
Defender update causes scan failures after zero-day patch; users advised to update Security Intelligence to 1.457.236.0 or later. #CyberSecurity #WindowsDefender #ZeroDay #ShieldBreak #Microsoft thedailytechfeed.com/windows-defe...
August 19, 2026 at 1:22 PM
Ερευνητής ασφαλείας αποκάλυψε τη zero-day ευπάθεια ShieldBreak στο Windows Defender, η οποία παρέχει πλήρη δικαιώματα SYSTEM στα Windows 11. #WindowsDefender #ShieldBreak #CyberSecurityNews
Windows Defender: Zero-day ευπάθεια «ShieldBreak» αποκαλύφθηκε από δυσαρεστημένο ερευνητή ασφαλείας
Ο ερευνητής «Nightmare Eclipse» δημοσίευσε κώδικα proof-of-concept που επιτρέπει την κλιμάκωση δικαιωμάτων σε επίπεδο SYSTEM στα Windows 11, παρακάμπτοντας τα προηγούμενα patches της Microsoft.
gr.pcmag.com
August 14, 2026 at 11:50 AM
Sicherheitsforscher Nightmare Eclipse hat direkt nach dem #Patchday einen weiteren #Zero-Day-#Exploit für den #WindowsDefender veröffentlicht und umgeht damit einen früheren Patch von #Microsoft. #Windows11
Windows: Sicherheitsforscher düpiert Microsoft mit zehntem Zero-Day
winfuture.de
August 13, 2026 at 1:34 PM