Ascension Global Technology

Ascension Global Technology Trusted by our clients and partners worldwide since 2015.

Ascension Global Technology delivers strategic cybersecurity services, identity protection, and managed IT services to help organizations strengthen defenses, reduce risk, and accelerate growth. Our approach is simple, we are an extension of your team and your trusted advisors every step of the way. AGT offers security protection through VCISO consulting, ransomware advisory services, cybersecurit

y strategy, research of leading security technologies, managed services, project management and cyber training. With services designed to improve any organization’s overall security posture, AGT white glove approach provides our clients successful cyber security programs to protect companies from cyber crime, data and financial loss.

Remember last week when we talked about “computers that aren’t computers”? Well, we can add the office phone system to t...
09/04/2026

Remember last week when we talked about “computers that aren’t computers”? Well, we can add the office phone system to the list.

Researchers are seeing active exploitation of a critical vulnerability in Sangoma Switchvox, an enterprise VoIP platform used for business communications. The vulnerability can allow an attacker to execute code remotely without credentials, and researchers have observed attackers establishing reverse shells on compromised systems.

It’s a real-world reminder that cybersecurity isn’t limited to the devices we traditionally think of as computers. A business phone system is still software running on a network-connected system—and it can become part of your organization’s attack surface.

Organizations should maintain visibility into network-connected and internet-facing systems, clearly define patching responsibilities, use network segmentation to limit access, and monitor these systems for unusual activity.

At AGT, we help organizations understand their real-world attack surface and make sure security controls extend across the entire technology environment—not just the devices that immediately come to mind.

Sometimes the most important question isn’t, “Are our computers secure?”

It’s, “Do we know everything on our network that is actually a computer?”

Article: https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html

Attackers exploit a patched Switchvox SQL injection flaw to deploy reverse shells, with about 4,000 instances exposed online.

You have a strong password. You’ve never shared it. Then you learn someone accessed your account anyway — through anothe...
09/03/2026

You have a strong password. You’ve never shared it. Then you learn someone accessed your account anyway — through another account you didn’t even know existed.

That’s essentially what happened to thousands of Dropbox users through a legacy integration with Lenovo.

A flaw in Lenovo’s email verification process allowed unauthorized Lenovo IDs to be created using other people’s email addresses. Because of the way Lenovo ID and Dropbox were connected, those identities could then be used to access corresponding Dropbox accounts without knowing the Dropbox password. Some affected users had never even created a Lenovo account.

The lesson goes beyond passwords: when one system trusts another to verify identity, that trust becomes part of the security equation.

So, what can we do?

For individuals:
• Enable MFA wherever it’s available.
• Review active sessions, connected apps, and account access.
• Pay attention to unexpected login, verification, or account-change notifications.

For organizations:
• Audit third-party authentication, SSO, and identity relationships.
• Review and retire unnecessary legacy integrations.
• Require strong verification before linking identities or accounts.
• Monitor for unusual authentication activity.

A strong password still matters. But protecting our identities and data also depends on the systems connected to our accounts — and the trust between them.

Article: https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/

Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs.

Few messages get our attention faster than one that appears to be about our health.The American Hospital Association is ...
09/02/2026

Few messages get our attention faster than one that appears to be about our health.

The American Hospital Association is warning about phishing campaigns impersonating MyChart through fraudulent emails, texts, calls, and websites designed to look legitimate.

The concern goes beyond whether the technology itself was compromised. When attackers can convincingly imitate a trusted healthcare platform and reach patients with messages designed to prompt action, the trust surrounding that platform becomes part of the attack surface.

Healthcare organizations can help by strengthening identity and access controls, monitoring for suspicious activity, clearly communicating how they contact patients, and preparing teams for phishing and impersonation scenarios.

For patients, remember: if an unexpected message asks you to take action involving your health information, don’t let the message choose how you get there. Open the trusted app or navigate to your provider’s known website independently.

Protecting healthcare information also means protecting the trust people place in the systems that hold it.

https://www.aha.org/news/headline/2026-08-24-mychart-warns-phishing-schemes-using-fraudulent-emails-other-messages

Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.”

Patched doesn’t always mean remediated.The recent PaperCut incident is a good example of why.PaperCut disclosed active e...
09/01/2026

Patched doesn’t always mean remediated.

The recent PaperCut incident is a good example of why.

PaperCut disclosed active exploitation of two vulnerabilities affecting its NG and MF software on August 27. An emergency patch followed on August 28. But after additional security research, PaperCut released a second emergency patch later that same day with additional hardening — and instructed customers to install it even if they had already applied the first update.

The sequence is an important reminder: installing the patch is essential, but it may not be the end of the response.

When a vulnerability is being actively exploited, organizations should be asking two questions:

1. Have we closed the vulnerability?
2. Was there activity in our environment before we closed it?

That means following the latest vendor guidance, confirming affected systems were updated, reviewing logs and security telemetry for suspicious activity, reducing unnecessary exposure, and being prepared to move into incident response if compromise is suspected.

Because at some point, vulnerability remediation can become incident investigation.

At AGT, we help organizations look beyond the checkbox by assessing exposure, validating security controls, managing cybersecurity vendors, and preparing teams for real-world incidents.

Read PaperCut’s security advisory:
https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/

Short description of what is in the security bulletin

Finding out your information was involved in a data breach can leave you with a very practical question: What should I d...
08/31/2026

Finding out your information was involved in a data breach can leave you with a very practical question: What should I do now?

Manchester Airports Group (MAG) recently disclosed that an unauthorized party accessed customer data associated with Wi-Fi registrations and services such as parking, lounges, and Fast Track bookings.

The exposed information includes email addresses, phone numbers, vehicle registration numbers, and postcodes. Payment information was not accessed.

For affected travelers, the most important part of this story may be what comes next. Exposed information can make suspicious emails, texts, and calls seem more convincing because they may contain details you recognize.

If you learn that your information has been involved in a breach:

• Read the notification carefully to understand exactly what information was exposed.

• Be cautious with unexpected emails, texts, or calls related to the affected organization. Go directly to its official website rather than following an unexpected link.

• Update passwords if credentials may have been affected or reused, and enable multi-factor authentication wherever possible.

• Monitor relevant accounts for activity you don’t recognize.

• Take advantage of identity or credit-monitoring resources when appropriate for the information exposed.

The right response depends on what information was compromised. Knowing what was exposed—and taking a few deliberate steps afterward—can help you respond appropriately without unnecessary alarm.

At AGT, we believe cybersecurity awareness should help people feel prepared to act when incidents happen.

Read more:
https://www.bleepingcomputer.com/news/security/manchester-airports-group-says-hackers-stole-travelers-data/

The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports.

You don’t need to be a Fortune 500 company to face Fortune 500-sized cybersecurity challenges.For many mid-sized organiz...
08/28/2026

You don’t need to be a Fortune 500 company to face Fortune 500-sized cybersecurity challenges.

For many mid-sized organizations, that’s the difficult reality. The business may have a smaller IT team, a tighter security budget, and fewer specialized resources — while still managing sensitive data, critical systems, third-party connections, and customers who depend on them.

New research highlighted by Cybersecurity Dive found that medium-sized businesses accounted for approximately 73% of ransomware incidents analyzed between 2023 and the first half of 2026.

The takeaway isn’t that mid-market organizations need enterprise-sized cybersecurity programs. It’s that limited resources need to be focused where they can make the greatest difference.

That means maintaining visibility into critical assets, strengthening identity and access controls, understanding third-party risk, and testing incident-response plans before they’re needed.

At Ascension Global Technology (AGT), we help organizations make those decisions thoughtfully — from assessing risk and deploying security controls correctly to managing cybersecurity vendors and preparing teams for real-world incidents.

Cybersecurity maturity isn’t about having unlimited resources. It’s about using the resources you have where they matter most.

Article: https://www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257/

These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite.

What would you do if someone called claiming to be a member of your security team — and they knew the name of the person...
08/27/2026

What would you do if someone called claiming to be a member of your security team — and they knew the name of the person they were impersonating?

That’s worth considering after a recent social engineering attempt targeting cybersecurity company ReliaQuest.

According to ReliaQuest, attackers created a lookalike domain and fake company SSO page, then called employees while posing as security personnel by name. One employee entered their password and approved an MFA notification, briefly giving the attacker access to their identity dashboard.

But additional security controls stopped the attack from going further. ReliaQuest says no applications or internal systems were accessed, and no customer data was touched.

There are two important lessons here.

First, social engineering can be difficult to identify when the person contacting you appears to know your organization. Employees need a simple, trusted way to independently verify unexpected requests involving passwords, MFA or account changes.

Second, people shouldn’t have to be the organization’s last line of defense.

Strong identity and access controls can help ensure that one successful social engineering attempt doesn’t automatically become a much larger compromise.

Organizations should regularly review identity and access controls, establish clear verification procedures, monitor identity activity for suspicious behavior, and test these scenarios through assessments and tabletop exercises.

At Ascension Global Technology, we help organizations evaluate how their people, processes and security controls work together — because resilience shouldn’t depend on any single layer working perfectly every time.

https://cybernews.com/security/shinyhunters-reliaquest-breach-okta/

ShinyHunters claims to have breached cybersecurity firm ReliaQuest, posting screenshots of its Okta dashboard.

Strong authentication only works if we’re confident the right person is behind it.Organizations have made significant pr...
08/26/2026

Strong authentication only works if we’re confident the right person is behind it.

Organizations have made significant progress with MFA and other identity controls. But a recent BleepingComputer article highlights another important question: How do we verify someone’s identity when trust needs to be established or restored?

During onboarding, account recovery, password resets, or MFA changes, verification may rely on employee IDs, phone numbers, security questions, identification documents, or visual confirmation. But personal information can be exposed, documents can be manipulated, and technologies like deepfake video and cloned voices are changing how much confidence we can place in any one signal.

The lesson isn’t to distrust every request. It’s to make sure the level of verification reflects the level of risk.

Organizations can strengthen that process by reviewing verification procedures, requiring greater assurance for higher-risk requests and privileged accounts, monitoring activity after sensitive identity changes, and testing these scenarios through assessments and tabletop exercises.

At Ascension Global Technology (AGT), we help organizations strengthen identity security, identify gaps between technology and process, and prepare teams for real-world incidents.

When someone says, “It’s me,” how does your organization determine when it has enough evidence to say, “We believe you”?

Article: https://www.bleepingcomputer.com/news/security/from-fake-workers-to-account-recovery-the-growing-identity-verification-risk/

Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and social engineering attacks from gaining legitimate access.

Address

260 1st Avenue S. #149
Saint Petersburg, FL
33701

Opening Hours

Monday 8am - 6pm
Tuesday 8am - 6pm
Wednesday 8am - 6pm
Thursday 8am - 6pm
Friday 8am - 6pm

Alerts

Be the first to know and let us send you an email when Ascension Global Technology posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share