Hits Safe Mode: Ransomware Rebooting Around EDR

Reported 12 Aug 2026 by otx · Severity: medium

An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using Wi