Akira ransomware disables EDR via Safe Mode, steals data but no encryption
An Akira ransomware affiliate bypassed endpoint detection by rebooting the infected system into Safe Mode with Networking to disable the EDR solution, stealing data without encrypting files.