Back to Secure AF - A Cybersecurity Podcast

Podcast Episode

Akira Ransomware Uses Safe Mode to Blind EDR: Lessons for Defenders

Secure AF - A Cybersecurity Podcast·Alias Cybersecurity·30 August 2026·6 min

About this episode

Got a question or comment? Message us here!Akira ransomware operators have demonstrated how abusing Windows Safe Mode can effectively disable or bypass endpoint detection and response (EDR) tools, underscoring the need for defenders to harden recovery environments, monitor Safe Mode activity, and implement layered detection controls that remain effective even during system startup changes.Support the showWatch full episodes at youtube.com/@aliascybersecurity. Listen on Apple Podcasts, Spotify and anywhere you get your podcasts.