Check out our companion blog!

Episodes

July 27, 2026

Stopping Ransomware Lateral Movement Before It Spreads

Ransomware lateral movement is exactly what it sounds like — once an attacker's inside your network, they start crawling around looking for more to encrypt, and stopping that crawl is often the difference between a bad day and a catastrophe. In this encore episode, part four of our seven-episode series pulling the best of the archives back into your feed, W. Curtis Preston and Prasanna Malaiyandi sit down with networking expert Tom Hollingsworth to break down exactly how attackers move once they...
July 20, 2026

Ransomware Response Checklist: Prevent It, Slow It, Survive It

This episode is built around a ransomware response checklist — a three-part Reddit series by a security specialist who goes by snorkel42, breaking down exactly how to prevent, contain, and recover from a ransomware attack. This is an encore episode, and it's back not just because a lot of people downloaded it originally, but because so many of you listened all the way through — some of you more than once. That kind of engagement told us this one was worth bringing back. Curtis Preston and Pras...
July 13, 2026

How to Protect Backups from Ransomware (Encore)

How to protect backups from ransomware starts with a hard truth: attackers aren't just encrypting your data anymore, they're stealing it first — and no backup system on earth undoes an exfiltration. In this encore episode of The Backup Wrap-Up, Curtis and Prasanna dig into what real immutability looks like versus the marketing version, why root access quietly undermines most "immutable" storage claims, the difference between virtual and true physical air gaps, and the exact questions you should ...
July 6, 2026

What Is Data Deduplication? (Encore)

What is data deduplication, and why does Curtis call it the single most important development in backup over the last 30 years? In this encore episode, W. Curtis Preston and Prasanna Malaiyandi break down exactly how dedupe works, why it's not the same as compression, and why the fine print of your dedupe domain determines how much storage you actually save. This episode originally aired as part of the Backup to Basics series, and it's back because listeners couldn't get enough of it — not just...
June 22, 2026

The REDCap Attack that Phishing-Resistant MFA Could Have Stopped

Phishing-resistant MFA could have stopped a Chinese state-sponsored threat actor from spending over a year inside North American academic and medical research networks — and we're going to tell you exactly how it happened and what you need to do about it. A group called UNC5608, tracked by Google's Threat Intelligence Group (GTIG), exploited a vulnerability unique to REDCap — a research data platform that allows multiple software versions to run simultaneously. They got in via stolen admin cred...
June 15, 2026

California Election Fraud? (Pt 2)

California election fraud claims are flooding social media — and most of them fall apart under basic scrutiny. In this follow-up episode, longtime San Diego County poll worker W. Curtis Preston tackles the wave of viral fraud allegations head-on, with sources so you can check his work yourself. Topics covered: the LA mayoral race "statistically impossible" surge for Nithya Raman, the AP reporting error that got blamed on fraud, claims that Spencer Pratt voters were having ballots rejected for s...
June 8, 2026

California Election Counting Explained by an Actual Poll Worker

California election counting has confused — and frankly ticked off — a lot of people, and I get it. I'm W. Curtis Preston, I've worked every California election since the 2016 presidential primary, and I've managed the polls at multiple elections here in San Diego County. This episode, I'm going solo to explain exactly what's going on, why it takes so long, what the "red mirage" actually is, and why none of it is fraud. Sorry to disappoint some of you. If you've ever had a family member call yo...
May 25, 2026

Stop 90% of Ransomware Attacks with Basic Cyber Hygiene

Basic cyber hygiene — patch management, password management, and MFA — is responsible for stopping roughly 90% of the ransomware attacks that could hit your organization. This episode is the overview: what those three things are, why they matter, and what happens when you skip them. WannaCry infected over 200,000 systems worldwide. A patch existed. People just hadn't applied it. Rackspace lost an entire business line — not because the attack was sophisticated, but because a workaround gave them...
May 18, 2026

Claude Deletes a Company — But It's Not Really Claude's Fault

Claude deletes a company — and the internet immediately blamed the AI. But this story is really about backup design, credential management, and least privilege. An AI coding agent running Claude via Cursor deleted PocketOS's entire production database and all its backups in nine seconds. One bad design decision at a time, a startup built itself a disaster waiting to happen. Claude just happened to be the thing that set it off. Here's what you need to understand: the AI violated the principles i...
May 11, 2026

How Honeypots and Canary Files Catch Attackers Before They Strike

Honeypots and canary files are two of the most underused tools in cybersecurity — and in this episode, Dr. Mike Saylor and I break down exactly how they work and why you should be using them. The short version: they're tripwires. They tell you a bad guy is poking around your network before anything gets encrypted. Mike walks through his layered security analogy, explains the three different ways organizations use honeypots — learning attacker tactics, distraction, and testing — and then we get ...
May 4, 2026

Network Segmentation to Prevent Ransomware: What the UCSF Attack Taught Us

Network segmentation to prevent ransomware isn't just a nice-to-have — the UCSF ransomware attack proves it's what separates a contained incident from a catastrophe. UCSF got hit. Their segmented network kept the damage from spreading across their entire operation. That's the difference we're talking about in this episode. Dr. Mike Saylor — my co-author on Learning Ransomware Response and Recovery — joins me and Prasanna to break down exactly how network segmentation works, why it matters for r...
April 27, 2026

Stop Using VSS as a Backup Before Ransomware Deletes Your Shadow Copies

Stop Using VSS as a Backup Before Ransomware Deletes Your Shadow Copies Ransomware deletes shadow copies using your own built-in Windows tools against you — and if VSS was your backup plan, you just found out the hard way that it wasn't. In this episode, W. Curtis Preston (Mr. Backup), Prasanna Malaiyandi, and Dr. Mike Saylor break down exactly what shadow copies are, why they don't qualify as a real backup, and how attackers are weaponizing vssadmin to wipe your recovery options before you even...
April 20, 2026

Ransomware Sanctions, OFAC, and the Lazarus Group: A Real Case Study

Ransomware sanctions are something most companies never think about — until they're staring down a ransom demand from a group the US government has already put on a sanctions list. In this episode, Dr. Mike Saylor walks us through a real incident involving a construction company, hundreds of millions in active contracts, and the Lazarus Group — a North Korean state-sponsored threat actor. Before that company could pay a single dollar in ransom, they had to figure out whether doing so would trigg...
April 13, 2026

The Real Cost of a Ransomware Attack: The Ransom Is the Least of Your Problems

The cost of a ransomware attack goes way beyond the ransom itself — and most organizations don't find that out until it's too late. In this episode of The Backup Wrap-up, W. Curtis Preston (Mr. Backup) and co-host Prasanna Malaiyandi sit down with Dr. Mike Saylor of Black Swan Cybersecurity to walk through every category of cost that hits when ransomware strikes. The case that kicks everything off: UVM Health Network, October 2020. Over 1,300 servers encrypted, staff forced back to paper record...
April 6, 2026

How Polymorphic Malware Evades Detection — And What to Do About It

Polymorphic malware is the kind of threat that changes its own code — its signature, its behavior, even the command-and-control server it reports to — specifically so your antivirus can't catch it. In this episode, Dr. Mike Saylor of Black Swan Cybersecurity joins Prasanna and me to break down exactly how this works, why signature-based detection keeps losing the race, and what defenders actually need to do differently. Mike walks us through ViraLock, one of the most well-known early examples o...
March 26, 2026

Emergency Episode: The PyPI Software Supply Chain Attack You Need to Know About

A PyPI software supply chain attack hit LiteLLM — a library pulled into developer environments 97 million times a month — and if you use it, you may already be compromised. This wasn't a fake package or a typo-squatting trick. Attackers stole real credentials, published malicious code as the real thing, and walked out with SSH keys, cloud credentials, Kubernetes tokens, API keys, and more — all encrypted and sent home before anyone knew what happened. I'm doing something I've never done before:...
March 23, 2026

Fileless Malware: The Attack That Lives in Memory

Fileless malware is one of the most dangerous attack types out there — it never writes to your hard drive, lives entirely in RAM, and can steal your credentials before your antivirus has any idea it's there. In this episode, I bring in Dr. Mike Saylor — my co-author on Learning Ransomware Response & Recovery — to break down exactly how this attack works, why it's so hard to detect, and what you can actually do to protect yourself. Mike walks us through how fileless malware hides in memory, how ...
March 16, 2026

Living Off the Land Attack: Hackers Using Your Own Tools Against You

A living off the land attack is one of the sneakiest techniques in a ransomware operator's playbook — and in this episode, Dr. Mike Saylor breaks down exactly what it is, how it works, and what your organization can actually do about it. Instead of bringing their own tools into your environment (which might trip your alarms), attackers just use what's already there. PowerShell. WMI. RDP. The same tools your admins run every single day. To your monitoring systems, it looks completely normal. Tha...
March 9, 2026

New Research Exposes Password Manager Vulnerabilities in LastPass, Bitwarden & Dashlane

Password manager vulnerabilities aren't just about bad code — and a new research paper out of Zurich just proved it. Researchers analyzed three of the most popular password managers and found fundamental design flaws baked into the very architecture that's supposed to keep your credentials safe. Curtis and Prasanna break it all down and tell you what to do about it. If you've ever been that person who asks "but what if the password manager gets hacked?" — this episode is for you. And if you hav...
March 2, 2026

What Is an Initial Access Broker — and Why Should You Care?

What is an initial access broker — and why does it matter to your organization? In this episode, W. Curtis Preston and Prasanna Malaiyandi are joined by Dr. Mike Saylor of Black Swan Cybersecurity to break down the role of the initial access broker in today's ransomware attacks. Most people picture ransomware as a single bad guy with a keyboard. The reality is way scarier. There's an entire criminal supply chain out there, and the initial access broker is the specialist at the front of it. Thes...
Feb. 23, 2026

Ransomware as a Service: How Anyone Can Buy a Cyberattack

Ransomware as a service has turned cybercrime into a franchise business — and in this episode, Dr. Mike Saylor and I break down exactly how it works, who's buying, and why the buyer might end up as the patsy. If you thought ransomware was just a lone hacker writing code in a basement, this episode is going to change how you think about it. Ransomware as a service means that today, literally anyone — no technical skills required — can pay someone to launch a ransomware attack on their behalf. Yo...
Feb. 16, 2026

The CryptoLocker Virus and the Birth of Modern Ransomware

The cryptolocker virus was the attack that turned ransomware from a nuisance into a full-blown criminal industry — and in this episode of The Backup Wrap-up, we break down exactly how that happened. W. Curtis Preston (Mr. Backup) sits down with co-host Prasanna Malaiyandi and cybersecurity expert Dr. Mike Saylor to trace the full evolution of ransomware and explain why CryptoLocker was the turning point. If you've ever wondered how ransomware went from fake pop-up messages to billion-dollar cri...
Feb. 9, 2026

A Brief History of Ransomware

A history of ransomware is more than just dates and names—it's the story of how criminals evolved from mailing infected floppy disks in 1989 to running billion-dollar enterprises that cripple entire organizations. On this episode of The Backup Wrap-up, I sit down with Dr. Mike Saylor, my co-author on "Learning Ransomware Response and Recovery," to trace this evolution from the AIDS Trojan to today's sophisticated double extortion attacks. We talk about how ransomware went from requiring physica...
Feb. 2, 2026

How Ransomware Works: The Five Objectives of Every Attack

Understanding how ransomware works is critical for anyone responsible for protecting their organization's data. In this episode of The Backup Wrap-up, we examine the five core objectives that drive nearly every ransomware attack - from initial access through the final ransom note delivery. I'm joined by my co-author Dr. Mike Saylor as we kick off what's going to be a comprehensive series on our new book, "Learning Ransomware Response and Recovery." We start at the beginning: how do these attack...