Hits Safe Mode: Ransomware Rebooting Around EDR
Reported 12 Aug 2026 by otx · Severity: medium
An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using Wi