THEMETASEC

Cybersecurity News, Aggregated

Akira Ransomware Uses Safe Mode to Bypass EDR

Security Affairs · 12 hours ago Breach

Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security […]

Read full story at Security Affairs →