Cybersecurity researchers have identified a new tactic where Akira ransomware affiliates use Windows Safe Mode to disable Endpoint Detection and Response (EDR) tools.
While the hackers successfully bypassed security measures to steal sensitive data, the attack failed to encrypt the victim's files due to a technical error.
The incident highlights a growing trend of threat actors exploiting system-level modes to evade modern cybersecurity defenses.