Huntress Labs reported that an Akira ransomware affiliate successfully disabled endpoint security on a victim's Windows server by rebooting it into Safe Mode, effectively circumventing protections. However, this action also prevented the ransomware from encrypting files as intended.