First Akira Safe Mode attack disables endpoint detection and response but fails to encrypt, Huntress says
Akira ransomware tried a new trick: Safe Mode. It disabled security. Then it broke itself.

Why it matters
A novel ransomware attack vector highlights the cat-and-mouse game between threat actors and defenders — and shows how attackers are learning to exploit OS-level mechanics against AI-native security tools. Practitioners need to know this tactic exists and how it failed.
The key facts
11 to knowAkira affiliate rebooted Windows server into Safe Mode
Safe Mode disabled third-party endpoint detection and response (EDR) tools
Attack failed: ransomware also broke in Safe Mode environment
Safe Mode loads only core Windows drivers; third-party security sits outside that set
First reported instance of this Akira variant technique
Huntress Labs identified and reported the attack
Akira ransomware affiliate used Safe Mode reboot to disable endpoint detection and response (EDR)
Safe Mode attack disabled third-party security products but also broke the ransomware's encryption capability
Safe Mode loads only core Windows drivers; third-party security sits outside that minimal set
First documented case of this technique against Akira variant
Discovered and reported by Huntress Labs
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke the ransomware. Safe Mode loads only core Windows drivers and services. Third-party security products…
