Patch for Windows Defender 0-day could allow attackers to fill hard disk

2026-07-13T08:51:47Z25a2433c9b71bd7961d7c81e431f1b9e0d5f22b8d65d5fd30ba730bdc6eec424
denial-of-servicemicrosoftnightmareeclipsepatchsecurity-updatevulnerability-disclosurewindowswindows-defenderzero-day

What happened

Ars Technica reports Microsoft released a patch for a Windows Defender zero-day that can be abused to fill a victim's hard disk (denial-of-service). The issue surfaced amid a public dispute between researcher(s) known as NightmareEclipse and Microsoft; Microsoft appears to have addressed this and related disclosures. Users are advised to apply the security update promptly — no CVE identifier was referenced in the article.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
25a2433c9b71bd7961d7c81e431f1b9e0d5f22b8d65d5fd30ba730bdc6eec424
Enrichment time
2026-07-13T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.