Akira ransomware scum blocked victim's security tools – and broke their own encryptor
Gives a whole new meaning to Safe Mode
Gives a whole new meaning to Safe Mode
An Akira ransomware affiliate attempted to evade endpoint detection and response tools by rebooting into Safe Mode to disable EDR and Windows Defender, but the technique backfired when the ransomware itself failed to execute in that environment. Huntress has documented the complete attack chain showing how this evasion tactic ultimately hindered the attacker's own encryption capabilities. The incident highlights the double-edged nature of Safe Mode abuse, where defensive measures can inadvertently impede malicious payloads.
AI has moved from experimental pilot programs to embedded production systems in security operations centers, with 97% of SOC teams reporting positive outcomes—yet security executives are notably more concerned than frontline staff about data governance, accountability, and risk management. The confidence gap reflects a maturity shift: operational teams validated that AI works, while leaders now grapple with harder questions about governance, oversight, and what happens when AI systems fail. The organizations pulling ahead aren't choosing between AI and human expertise; they're building models where AI handles volume and pattern matching while analysts retain decision authority, and buyers increasingly expect transparency into how AI decisions are made rather than simply faster automation.
The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency, and team spirit are key factors.
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
All versions of Siemens RUGGEDCOM APE1808 are affected by two Fortinet vulnerabilities: a cross-site scripting flaw (CVE-2026-23573, CVSS 6.1) that allows authenticated remote users to execute code via crafted requests, and a path traversal vulnerability (CVE-2026-59839, CVSS 5.5) exploitable by privileged authenticated attackers with physical access to delete the file system. Siemens recommends contacting customer support and following Fortinet's mitigation guidance, while CISA advises minimizing network exposure and isolating control system networks from the internet.
Security researchers demonstrated a vulnerability in Boeing 737 aircraft where a small, coin-sized device can be physically inserted into an external hatch in under 60 seconds to compromise critical flight systems. The attack allows an attacker to redirect the aircraft's autopilot or modify its flight plan, highlighting a significant physical security gap in commercial aviation.
Victoria is the first stop as privacy campaigners warn the technology is becoming routine
Criminal organizations are escalating cargo theft tactics to unprecedented levels of violence in California, specifically targeting high-value AI hardware and data center equipment. Security experts point to at least two recent incidents as evidence that theft rings view these server shipments as lucrative enough to employ increasingly dangerous methods to intercept them.
The Polish CERT has released details of another 2025 attack on a combined heat and power plant in the country
Microsoft addressed 400 vulnerabilities across its product portfolio in its August Patch Tuesday release. The substantial update volume underscores the ongoing volume of security issues requiring remediation across Microsoft's software ecosystem.
The Agent Baseline defines 35 controls across six security outcomes—but the right starting point depends on how your organization uses agents. Learn how to sequence controls for coding, internal, and production agents.
Microsoft's August 2026 Patch Tuesday release addresses 421 vulnerabilities across its product portfolio, including 62 critical and 357 important-severity issues, with three zero-day vulnerabilities patched—two publicly disclosed and one actively exploited in the wild. The update underscores the ongoing threat landscape where timely patching remains essential for enterprises to reduce exposure and mitigate attack surface.
One big caveat, though: You need your contact's phone number
Microsoft's August Patch Tuesday release includes CVE-2026-62878, a critical remote code execution vulnerability in Windows DNS Server with a CVSS score of 9.8 that requires no user interaction. This RCE flaw represents a significant risk to organizations running affected DNS Server infrastructure and should be prioritized for immediate patching.
Sysadmins, welcome to your new norm
Microsoft released patches for nearly 400 security vulnerabilities across Windows operating systems and supported software, addressing multiple flaws that posed immediate risk to users. The update included at least one vulnerability already under active exploitation and two additional weaknesses that had been publicly disclosed before the patch release.
The Gunra ransomware gang is actively exploiting known Fortinet vulnerabilities and leveraging leaked Conti code to compromise critical infrastructure targets while circumventing multi-factor authentication. The group's success against defended environments suggests that unpatched firewall and VPN appliances remain a significant attack surface, even when MFA protections are in place.
August 2026 Patch Tuesday brings 421 vulnerabilities including a critical SharePoint RCE chain discovered by Rapid7 researchers and an actively exploited Windows Ancillary Function Driver elevation-of-privilege flaw, while the pseudonymous researcher "Nightmare Eclipse" continues a pattern of late-cycle disclosures with ShieldBreak, a patch bypass for previously patched Defender vulnerabilities. Microsoft Edge received delayed security patches compared to Chrome, with a five-day gap between Chrome and Edge updates marking an unusual slowdown in the browser's typical patching cadence.
Microsoft's August 2026 Patch Tuesday addressed 398 CVEs across a broad range of products, with 42 rated critical and three zero-days including one actively exploited in the wild. Notable vulnerabilities include a critical remote code execution flaw in Windows Deployment Services TFTP Server with a CVSS score of 9.8, a critical Windows DHCP Server RCE affecting unauthenticated remote attackers, and the actively exploited Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability. Elevation of privilege vulnerabilities accounted for 40.7% of this month's patches, followed by remote code execution vulnerabilities at 27.1%.