Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.

An Akira ransomware affiliate recently attempted to deploy ransomware on a victim's network by first rebooting the compromised host into Safe Mode with Networking, a tactic aimed at disabling endpoint detection and response (EDR) tools. While the maneuver successfully bypassed security controls, the ransomware itself failed to execute due to memory constraints within the stripped-down Safe Mode environment.
The incident, which occurred on August 4, 2026, began with the attacker gaining initial access through an unauthenticated SonicWall VPN. Following the breach, the attacker spent approximately two hours enumerating Active Directory users and computers, archiving mapped file shares with WinRAR, and exfiltrating the data to an S3 bucket using s5cmd. This exfiltration phase occurred before any encryption attempt, meaning the victim remained susceptible to extortion despite the subsequent failure of the ransomware.
After data exfiltration, the attacker rebooted the victim's host into Safe Mode with Networking. This action effectively disabled the EDR solution and Windows Defender's real-time protection. To maintain remote access during the reboot, the attacker also added AnyDesk to the Safe Mode registry. For about ten minutes, the system operated without active security defenses.
However, when the `akira.exe` ransomware payload was launched at 06:34:29 UTC, it encountered an "Out of Virtual Memory" error approximately 13 seconds later. The report indicates that the ransomware's process tree, with its burst of child processes, overwhelmed the limited virtual memory available in Safe Mode, causing the encryption process to fail. Windows Defender's scheduled scan later detected `akira.exe` as `Ransom:Win32/Akira.B!ibt`, but could not quarantine it while real-time protection was disabled. The file was only removed after the attacker rebooted the system back to normal mode, which restored Defender's full functionality.
While other ransomware variants like Snatch and AvosLocker have previously been observed using Safe Mode to bypass security, this incident marks the first documented instance of Akira ransomware employing this technique. Researchers noted that the failure of the ransomware was a "lucky side effect" of the attacker's miscalculation regarding Safe Mode's memory limitations. They cautioned that a system with more RAM or a larger page file might have provided sufficient memory for the encryptor to succeed, or that Akira's developers could retool the payload to reduce its memory footprint, making future Safe Mode launches more reliable.
To detect similar attacks, security guidance recommends monitoring for `msconfig.exe` or `bcdedit` activity, Kernel-Boot Event ID 27 with a SAFEBOOT load option, Kernel-General Event ID 12 with BootMode=2, and the stopping of third-party services. Additionally, vigilance is advised for remote access tools being added to the Safe Mode service registry, as this often indicates an attacker's intent to maintain persistence through a reboot.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed