Windows Defender zero-day blocks antivirus updates
A newly disclosed Windows Defender exploit prevents Microsoft's antivirus from updating, potentially leaving systems unprotected.
Security researcher Abdelhamid Naceri, also known as Nightmare Eclipse, has published another Windows Defender zero-day exploit. The flaw prevents Microsoft's antivirus from receiving updates, which could leave systems vulnerable to new threats while the update mechanism is disrupted.
The exploit was released over the weekend, according to the report. No details about a patch or official mitigation were mentioned in the source, and it is unclear whether Microsoft has acknowledged the issue yet.
This is not the first time Naceri has disclosed a Defender flaw; the researcher has previously released similar exploits. The repeated disclosures highlight ongoing concerns about the security of Microsoft's built-in antivirus product.
Sources · 4
- NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
- Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
- Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
- New Windows Defender zero-day blocks Microsoft antivirus updates
More in Security & Privacy
Canada Probes IDScan After Breach of 153M Driver's Licenses
Privacy Commissioner opens investigation into IDScan.net's security practices and breach notifications after stolen ID scans of 153 million people appeared on the dark web.
AI Relay Servers Mask Chinese Access to US Frontier Models
More than 80,000 AI relay servers are helping users in China hide their identities while accessing cutting-edge US AI models, likely to clone them.
Sweden Fines Miljödata $183,000 for Breach Affecting 2.2 Million
Sweden's privacy regulator penalized IT provider Miljödata for security failures linked to a breach that exposed 2.2 million people's data.
Rogue External MFA Providers Can Steal Passwords in Login Attacks
Researchers show that attackers with privileged access can register a malicious external MFA provider that harvests passwords during otherwise legitimate logins.