'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates

A new proof-of-concept technique dubbed 'BigDiskBuster' has been identified, which allows attackers to disrupt Microsoft Defender's update mechanism without disabling the security service itself. By exploiting how the software manages disk space and update processes, the technique creates a silent detection gap. The security tool continues to run and report normal status to the user, but it fails to receive the latest threat intelligence signatures, leaving the system vulnerable to new exploits. Unlike traditional EDR-killer tools that attempt to terminate security processes, BigDiskBuster operates by manipulating the environment to prevent updates, making it harder for automated monitoring systems to detect the compromise. Security researchers highlight that this method requires no specific exploit, relying instead on the inherent logic of the update service. Organizations are advised to monitor for unusual disk activity and ensure that security updates are successfully applied across their infrastructure.
This is a summary. Read the full article at the original source:
Dark ReadingRelated stories
Hackers obtain counterfeit TLS certificates for Google and other large services
Google recently disclosed that attackers successfully hijacked three top-level domains (.gh, .sl, and .as) to issue counterfeit TLS certificates for v…
Online fashion retailer Asos has confirmed it is investigating a security incident involving an extortion hack. The attackers reportedly gained unauth…
Google has introduced PageBreak, an autonomous AI agent designed to enhance web application security by identifying vulnerabilities. In recent interna…



