Akira Ransomware Uses Windows Safe Mode to Shut Down EDR Before Launching Encryptor

Akira ransomware has added a new way to weaken Windows security before it tries to lock files. In a recent intrusion, an affiliate rebooted a compromised system into Safe Mode with Networking, leaving the device connected while most third-party protections stayed offline. The operation began with a credential-spraying attack against an exposed SonicWall SSL VPN […]

This article has been indexed from Cyber Security News

Read the original article: