Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Akira Ransomware Exploits Safe Mode to Bypass Security

Akira Ransomware Exploits Safe Mode to Bypass Security

Posted on August 13, 2026 By CWS

Akira ransomware is employing a novel technique to undermine Windows defenses before encrypting files. By rebooting compromised systems into Safe Mode with Networking, attackers maintain network connectivity while rendering many third-party security measures inactive.

Intrusion Tactics and Initial Access

The attack commenced with a credential-spraying offensive aimed at an exposed SonicWall SSL VPN lacking multi-factor authentication. Successful access was achieved using valid credentials, enabling the attackers to penetrate the network via remote desktop connection, subsequently mapping the network and exfiltrating vital data.

This method mirrors the vulnerabilities reported in recent SonicWall VPN breaches, highlighting the need for robust security protocols. Once inside, attackers swiftly leveraged remote access infrastructure, identifying critical systems, stealing data, and attempting encryption within a short timeframe.

Exploiting Safe Mode for Security Evasion

Security researcher Huntress noted this as the first observed case of Akira utilizing Safe Mode to disable endpoint detection and response (EDR) tools. This approach is significant due to Akira’s notoriety as a leading ransomware operation in 2025, where even unsuccessful encryption attempts can lead to data extortion.

After breaching the system, the attackers accessed the domain controller via Remote Desktop Protocol, extracting user and system data from Active Directory. Subsequently, they archived network shares using WinRAR, uploading them to cloud storage in preparation for encryption.

Challenges and Implications for Security Teams

To facilitate remote control, the attackers installed AnyDesk as a service, modifying the Safe Mode registry list to ensure its operation post-reboot. Initiating Safe Mode with Networking at 06:29 UTC, they temporarily disabled key defenses like Microsoft Defender, maintaining control through the remote-access service.

This strategy, though not novel, poses new challenges for security teams who must now consider unexpected boot configurations as high-priority threats. Moreover, even when the encryption failed due to virtual-memory constraints, the attackers had already exfiltrated credentials and files, setting the stage for a potential double-extortion scenario.

Preventive Measures and Future Outlook

The incident underscores the importance of multifactor authentication for VPN accounts and the need for prompt credential rotation following a compromise. Security teams should also centralize logging and monitoring to detect unusual activity patterns, such as failed login bursts followed by successful access from the same source.

By deploying comprehensive endpoint coverage and heeding lessons from past ransomware activities, organizations can better defend against intrusions and mitigate the risk of data theft or encryption. As ransomware tactics evolve, proactive measures remain crucial in safeguarding network integrity.

Cyber Security News Tags:Akira ransomware, credential-spraying, cyber threats, Cybersecurity, data encryption, endpoint detection, remote desktop access, Safe Mode, SonicWall VPN, Windows security

Post navigation

Previous Post: Critical Cisco Firewall Vulnerability Urges Immediate Action
Next Post: VMware vCenter Vulnerability Exploited by Hackers

Related Posts

Fake Video Players Spread Malware: Crypto Miner and RAT Fake Video Players Spread Malware: Crypto Miner and RAT Cyber Security News
Threat Actor Installed EDR on Their Systems, Revealing Workflows and Tools Used Threat Actor Installed EDR on Their Systems, Revealing Workflows and Tools Used Cyber Security News
LokiBot Campaign Revives with Advanced Evasion Techniques LokiBot Campaign Revives with Advanced Evasion Techniques Cyber Security News
Security Risk Advisors Unveils 2026 Cybersecurity Report Security Risk Advisors Unveils 2026 Cybersecurity Report Cyber Security News
Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily Cyber Security News
Iranian Hackers Breach FBI Director’s Email Iranian Hackers Breach FBI Director’s Email Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phantom Stealer Conceals in PNG Files, Targets Data
  • VMware vCenter Vulnerability Exploited by Hackers
  • Akira Ransomware Exploits Safe Mode to Bypass Security
  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phantom Stealer Conceals in PNG Files, Targets Data
  • VMware vCenter Vulnerability Exploited by Hackers
  • Akira Ransomware Exploits Safe Mode to Bypass Security
  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark