New 'BigDiskBuster' Technique Can Leave Microsoft Defender Running but Out of Date
Researchers have described a proof-of-concept technique named BigDiskBuster that targets Microsoft Defender in an unusual way. Rather than switching the antivirus off, it blocks updates while the Defender service keeps running as normal.
According to Dark Reading, this is not quite an EDR-killer, which is a tool built to disable endpoint security software outright. Instead, it creates a silent detection gap. The protection still looks active, but it may not recognise newer threats because it cannot receive fresh updates. The report also notes that no exploit is required to achieve this.
The risk for businesses is false confidence. A device showing a running antivirus service may appear healthy, even though its ability to spot new malware is slowly falling behind. The short summary we have does not detail how widely the technique has been seen or how it works, so defenders should watch for further guidance from Microsoft and the researchers.