An Akira ransomware affiliate rebooted a victims computer into Safe Mode to kill its security tools – and in the process sabotaged their own malware when the limited function startup mode also broke their encryptor. But the ending wasnt entirely happy for the victim. The attacker had already stolen credentials and data from file shares before Safe Mode prevented the ransomware from doing its job. Huntress security operations analyst James Northey detailed the incident in a Wednesday blog and...

Read the full article at The Register