Adlumin monitoring dashboard - layered detection that keeps watching when endpoint protection goes quiet
Adlumin monitoring dashboard - layered detection that keeps watching when endpoint protection goes quiet

Weekly Briefing • August 15, 2026

Three of the incidents we tracked this week have the same shape: the systems involved did exactly what they were built to do, and nobody got an alert. Ransomware ran on a server whose endpoint protection was installed, licensed, and correctly configured — Windows simply never started it. Hundreds of thousands of automated emails carrying credentials and personal details were delivered perfectly, to a stranger, because the sending domain belonged to somebody else. And a healthcare practice that spotted an intrusion in March finished telling its patients at the end of June.

None of these required a clever exploit. Here's what happened, and what each one is asking of your firm.

The Server Rebooted, and the Endpoint Protection Never Came Back

Huntress investigated an Akira ransomware intrusion that began with credential spraying against an internet-facing SonicWall SSL VPN. About seven minutes passed between the first failed login attempts and a successful sign-in — to an account that did not have multi-factor authentication enabled. Two hours later the operator was on the domain controller over RDP. Files from mapped shares were archived with WinRAR and copied out to attacker-controlled cloud storage, all of it finished before any encryption was attempted.

Then came the part worth understanding. The operator installed AnyDesk for persistent access, added AnyDesk to the Windows Safe Boot registry configuration so their own tool would still run, forced the server to reboot into Safe Mode with Networking, and launched the ransomware there. Safe Mode loads only essential drivers and services, and third-party security products are excluded from that set by design. Huntress's own agent and Microsoft Defender's real-time protection were not switched off or tampered with. They were never started. Defender did later identify the ransomware binary sitting on disk, but could not act on it until the machine was booted back into normal Windows.

Key Insight

The endpoint protection on that server was installed, licensed, and correctly configured, and it produced no telemetry at all — because Windows never loaded it. A control that isn't running doesn't fail loudly. It just goes quiet.

Two unglamorous things would have changed this story. The first is MFA on that VPN account: no SonicWall vulnerability was involved and no CVE was exploited — seven minutes of guessing found an account where a password alone was enough. The second is an alert when a server boots into Safe Mode without a change ticket behind it. Servers do not reboot into Safe Mode during normal operations, which makes it one of the cleaner alarms you can set. One footnote worth keeping straight: the encryption in this case actually failed, on virtual memory errors. Huntress is explicit that this was a coincidence of resource limits, not a defense. Full chain and detection guidance: Akira Ransomware Reboots Windows Into Safe Mode to Knock EDR Offline.

The "No Reply" Address in Your Software May Belong to a Stranger

Researcher Cory Solovewicz owns noreply.net and noreply.us — addresses that look like throwaway placeholders but are real, registrable domains that somebody can simply buy. Since December 2024, one of them has taken in 401,796 messages, by his own count around 700 a day, from more than 14,000 distinct sending addresses across roughly 6,200 root domains. Of the noreply.net messages, 28,365 arrived with attachments. What lands there is ordinary business mail: account-setup messages from a school platform, injury reports from a city government, Zoom invitations from a UK government agency, credentials from test and QA systems.

A second researcher, Mike Sheward, registered deleteduser.com for about fifteen dollars. Three organizations emailed it within the first hour, and he has since received unintended mail from at least a hundred of them. The cause sits in application code rather than in anyone's mail server. A developer needs a sender address, picks something that looks obviously fake, and happens to choose a domain that is real and available. Or a system replaces a departed employee's address with a placeholder instead of removing the record, and every workflow attached to that account keeps firing. Nothing in email checks that the domain in a From or Reply-To field is one the sender actually owns, so delivery succeeds and no alert is generated on either end. We made the point in the last briefing that a real email isn't automatically a safe email; this is the same lesson pointed the other direction, at the mail your own systems send.

For a practice, the systems worth checking are the obvious ones: practice management, your EHR, appointment reminders, the client or patient portal, e-signature and intake tools. If any of them is configured to send from a domain you don't own, then every activation link, temporary password, and appointment detail it has mailed went somewhere you can't see. Details and the full checklist: Researcher Buys noreply.net and Companies Start Emailing Him Secrets.

Three Months Between Finding It and Telling Anyone

Texas Hearing Institute, a pediatric audiology provider operating as The Center for Hearing and Speech, notified 29,744 patients after the Interlock ransomware group took files from its network. Interlock claims 540 GB. The data included names, Social Security numbers, diagnosis and treatment information, and financial account information. Interlock runs as a ransomware-as-a-service operation and works by double extortion: copy the files first, encrypt second, and charge separately for the decryption key and for not publishing what was taken. The ransom went unpaid, so the data was published.

The ransomware isn't the instructive part. The calendar is. Suspicious network activity was spotted on March 20, 2026. Forensic work confirmed the scope on or around April 22. The list of affected individuals was finalized on June 19, and notification letters went out on June 26 — roughly three months from "something is wrong on our network" to patients learning their records were involved. Most of that time goes into answering one question: whose data was actually in those 540 GB.

That answer is only as fast as your logging. If you can't show what was accessed and when, it has to be reconstructed from whatever evidence survived, and the clock runs the entire time. HIPAA's Breach Notification Rule allows 60 days from discovery for breaches affecting 500 or more people, which also pulls in HHS's Office for Civil Rights and, above that threshold, the media. When "discovery" legally occurred is exactly the kind of question that gets argued afterward, which is a good reason not to be in a position to argue it. The question worth putting to your own team: if this happened here on a Friday, how many days until we could produce a defensible list of exactly whose records were touched? Full breakdown: Interlock Ransomware Attack on Texas Hearing Institute Hits 30,000 Patients.

Also on Our Radar This Week

Microsoft patched 398 vulnerabilities this month, 42 of them critical — managed environments absorb this through the normal patch cycle without anyone thinking about it. The machines worth worrying about are the ones nobody manages: the personal laptop somebody uses for remote work, the old workstation in the back office that never got replaced.

Fake CCleaner downloads deliver the GhostDesk trojan — it hijacks Chrome to steal session cookies along with credentials and screenshots. Stolen session cookies matter because they hand over an already-authenticated session; nobody gets prompted for a second factor on a session that is already signed in.

A banned AI Sidebar Chrome extension is back in the Web Store carrying an affiliate-fraud payload — a browser extension can read every page the person using it opens, which includes your practice management system. Removal from the store isn't permanent, and a familiar name in the listing isn't a safety check.

One Thing to Do This Week

Open the last automated email one of your systems sent a patient or client — an appointment reminder, a portal invitation, a signature request — and look at the From and Reply-To addresses. You are checking one thing: is the domain after the @ one your practice owns? An address like This email address is being protected from spambots. You need JavaScript enabled to view it. is exactly right. An address at noreply.net, or at any domain that isn't yours, means that mail has been going to whoever owns it. Check each system that emails your clients; it takes about ten minutes and needs no help from IT.

Brian Sammons, Founder of Capstone Technologies Group

Brian Sammons has managed IT environments for Ohio professional service firms — medical, dental, legal, accounting, and financial — since 2002. He writes the Weekly Briefing for the owners, administrators, and IT managers responsible for keeping those firms running: what happened in security this week, and what it means for yours.

Questions about how this affects your environment? Schedule 15 minutes and I'll walk you through it.