[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fceeSSkQ4Wy129sGgLvAF5oZM5LY4WYEdXpMyG_Byb7s":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":22,"category":23,"article_tags":26},"81af70c9-d595-43eb-a10c-7b3d661efbd9","Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack","akira-ransomware-affiliate-rebooted-into-safe-mode-to-dodge-edr-and-broke-its-ow-d5ae34","An affiliate of the Akira ransomware operation attempted a novel technique to blind endpoint defences during a recent intrusion, rebooting a compromised server into Windows Safe Mode to knock out both an EDR agent and Microsoft Defender in one move, only for the same stripped-down environment to cause the ransomware payload itself to crash before […] The post Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attack appeared first on IT Security Guru.","An affiliate of the Akira ransomware operation attempted to bypass endpoint detection and response (EDR) by rebooting a compromised server into Windows Safe Mode. This maneuver successfully disabled both the EDR agent and Microsoft Defender. However, the stripped-down Safe Mode environment also caused the ransomware payload to crash, thwarting the attack.","Akira ransomware affiliate rebooted server into Safe Mode to evade EDR, but it broke the ransomware.",null,"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F08\u002F13\u002Fakira-ransomware-affiliate-rebooted-into-safe-mode-to-dodge-edr-and-broke-its-own-attack\u002F?utm_source=rss&utm_medium=rss&utm_campaign=akira-ransomware-affiliate-rebooted-into-safe-mode-to-dodge-edr-and-broke-its-own-attack","2026-08-13T11:59:58+00:00","2026-08-13T12:00:26.297294+00:00",7,[17,20],{"name":18,"type":19},"Windows Safe Mode","product",{"name":21,"type":19},"Microsoft Defender","7d8b5ab8-ea0b-4ced-ae97-ec251b86993a",{"id":22,"icon":11,"name":24,"slug":25},"Ransomware","ransomware",[27,29,34,39],{"category":28},{"id":22,"icon":11,"name":24,"slug":25},{"category":30},{"id":31,"icon":11,"name":32,"slug":33},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":35},{"id":36,"icon":11,"name":37,"slug":38},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":40},{"id":41,"icon":11,"name":42,"slug":43},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]