WorkThe story, in brief

First Akira Safe Mode attack disables endpoint detection and response but fails to encrypt, Huntress says

Akira ransomware tried a new trick: Safe Mode. It disabled security. Then it broke itself.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

A novel ransomware attack vector highlights the cat-and-mouse game between threat actors and defenders — and shows how attackers are learning to exploit OS-level mechanics against AI-native security tools. Practitioners need to know this tactic exists and how it failed.

The key facts

11 to know
  1. Akira affiliate rebooted Windows server into Safe Mode

  2. Safe Mode disabled third-party endpoint detection and response (EDR) tools

  3. Attack failed: ransomware also broke in Safe Mode environment

  4. Safe Mode loads only core Windows drivers; third-party security sits outside that set

  5. First reported instance of this Akira variant technique

  6. Huntress Labs identified and reported the attack

  7. Akira ransomware affiliate used Safe Mode reboot to disable endpoint detection and response (EDR)

  8. Safe Mode attack disabled third-party security products but also broke the ransomware's encryption capability

  9. Safe Mode loads only core Windows drivers; third-party security sits outside that minimal set

  10. First documented case of this technique against Akira variant

  11. Discovered and reported by Huntress Labs

Go to the source

SiliconAnglesiliconangle.com

Publisher excerpt: Huntress Labs Inc. said today that an Akira ransomware affiliate rebooted a victim’s Windows server into Safe Mode to knock its endpoint security offline — and it worked. The same reboot also broke the ransomware. Safe Mode loads only core Windows drivers and services. Third-party security products…
Read original report
Back to today's editionMore work news

The wider picture

View all
Illustration of independent geometric mechanisms passing paper tasks along branching amber tracks.
AI illustration by KeyNews
Work01

The Emerging M&A Map For AI Agent Security

As agents move from pilots to production with real system access, enterprise security models are breaking. The M&A map is forming around who controls agent permissions, monitoring, and governance — a new class of identity management problem that practitioners need to architect for now.

Crunchbase News
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work02

AI privacy budgets: Ask for the calculation, not the claim

Enterprise AI buyers are accepting privacy budget numbers without verification. This deep dive explains what questions to ask vendors about federated learning privacy claims, and why the gap between contractual promises and operational evidence is where real exposure lives.

CIO
Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
AI illustration by KeyNews
Work03

Andrew Kelley Interview: Why He Built Zig, Banned AI Contributions, and Moved Zig off GitHub

Open-source governance is shifting in response to AI-generated contributions. Zig's formal ban and migration off GitHub signals broader industry concern about code quality, maintainer burden, and the cultural impact of automated submissions — a flashpoint for how AI changes the work of software development.

InfoQ AI/ML