News

First Akira Safe Mode attack disables endpoint detection and response but fails to encrypt, Huntress says

  • Duncan Riley--SiliconANGLE News
  • published date: 2026-08-12 13:00:12 UTC

Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke the ransomware. Safe Mode loads only core Windows drivers and…

Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke t… [+6740 chars]