Akira rebooted the machine into Safe Mode to blind the EDR — the encryption still failed, and it did not matter
2026-08-17Security
Huntress traced a 4 August intrusion from an exposed SonicWall VPN with no MFA to a failed ransomware payload five hours later. The files were already in the attacker's S3 bucket. Defender quarantined akira.exe after the reboot, too late to matter.