Over-Privileged Service Accounts Pose Growing Security Risk as Machine Identities Surge
A common developer habit of granting broad permissions to integration accounts to unblock quick fixes — and never narrowing them — has created a widespread security vulnerability in modern software systems. According to CyberArk's 2025 Identity Security Landscape report, surveying 2,600 security decision-makers, machine identities now outnumber human ones 82 to 1, with 42% holding privileged or sensitive access. Yet 88% of organisations still define 'privileged user' as a human, meaning most privileged accounts fall outside the policies designed to govern them. The problem is compounded by the rise of AI agents, which unlike static scheduled jobs execute instructions based on runtime content, making over-privileged accounts exploitable through prompt injection — the top risk in the OWASP LLM Top 10. Security experts recommend assigning one scoped credential per workflow with defined owners and expiry dates, rather than relying on shared, broad-access accounts that outlive their original purpose.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in