Machine, Identities

Machine Identities Outnumber Humans 80 to 1 as CISA Gives Federal Agencies Until July 2 to Patch SimpleHelp Bug

Published on 07/01/2026 at 14:05 | Redaktion boerse-global.de

By 2025, machine identities outnumber human workers 80:1. Short-lived certificates replace static keys to slash risk. CISA orders SimpleHelp patch; Citrix fixes bugs. Automation and eIDAS 2.0 reshape identity management.

Machine IDs Outnumber Humans 80:1 by 2025 – Shift to Short-Lived Certificates
Machine Identities Outnumber Humans 80 to 1 as CISA Gives Federal Agencies Until July 2 to Patch SimpleHelp Bug Illustration mit AI erstellt ĂĽbermittelt durch boerse-global.de

By 2025, every human identity inside a company was already outnumbered by more than 80 machine identities — certificates, service accounts, API keys and bots that authenticate without a human at the keyboard. That explosion has forced organizations to rethink static access methods. Security experts now advocate replacing permanent SSH keys with short-lived certificates, a model already used by Google and Uber to slash the risk of credentials that never expire.

The urgency is underscored by how quickly attackers pounce. In 2018 it took more than two years for a vulnerability to be systematically exploited. By 2026 that window had collapsed to just a few hours.

The U.S. cybersecurity agency CISA responded by ordering federal agencies to close a critical hole in SimpleHelp remote?management software by July 2. Attackers are actively exploiting the flaw to impersonate technicians and deploy Djinn Stealer, a piece of malware designed to swipe login credentials from cloud environments and DevOps tools. The same week, Citrix shipped security patches for NetScaler ADC and Gateway. The six fixes cover denial?of?service bugs and memory errors. Cloud?hosted instances have already been updated; administrators of on?premises systems must apply the patches manually unless they have automated workflows in place.

Behind the patch?race sits a broader shift in how identity is managed. On July 1, several technology vendors launched new automation tools. Zoom introduced an AI?powered solution for virtual workspaces. Amazon Web Services released an environment for AI agents that supports the MCP management framework. Platforms like Tanium Atlas — already used by more than 1,300 organizations — bundle security modules into a single console, shortening patch cycles and giving real?time visibility into millions of endpoints.

Regulation is also pushing change. The expanded eIDAS 2.0 framework creates new standards for digital identities and signatures across Europe. Experts warn that companies must not treat user onboarding as an isolated step; authentication needs to break free from the old password logic. Compromised credentials remain the most common entry point for attacks on internal systems, especially among small and mid?sized businesses.

The economic upside of automated identity processes is visible in manufacturing. Digital product passports and certified data spaces — like those offered by Fraunhofer IESE — yield big time savings. One example: managing 100,000 assets with digital calibration certificates instead of paper saves up to 75,000 work hours per year.

A practical risk that automation can address is “permission creep” — the gradual accumulation of unnecessary access rights by employees. A webinar series hosted by Matrix42 starting July 8 will explore how companies can prevent that accumulation, which often hides the biggest compliance liabilities.

Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.

en | boerse | 69667259 |