← Back to feed
Breaches & RansomwareEmerging1 sourceAug 13, 2026 · 08:17via Cyber Security News

Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor

Brief

Akira ransomware has added a new way to weaken Windows security before it tries to lock files.

In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline.

The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN that had no multi-factor authentication.

A valid account opened the door, after which the intruder used remote desktop access, mapped the network, collected files, and prepared them for upload.

This route echoes the risks described in recent SonicWall VPN exploitation cases.

The attackers had already established a familiar, fast-moving playbook: entry through remote access infrastructure, rapid discovery of valuable systems, data theft, and then an encryption attempt within hours.

Read more on Cyber Security News