Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It is free until February 2027, though the window that prompted its creation is already closing.

Key points
- Oracle released a free tool called Database Security Central to help organisations monitor and protect their database environments.
- The tool is available at no charge until the end of February 2027.
- Oracle moved from quarterly to monthly security patches in May after an AI model called Mythos began hunting for software flaws at speed.
- The first monthly patch batch, released in May, fixed 35 separate security vulnerabilities, meaning flaws that attackers could exploit to break in or cause damage.
- Oracle databases are actively being targeted by attackers exploiting known weaknesses in the software.
Oracle, one of the world's largest makers of database software (programs companies use to store and organise their most sensitive information), has released a new security tool and is giving it away free for roughly two years. The timing is not a coincidence.
What pushed Oracle to act?
Attackers are actively going after known weaknesses in Oracle's database products, and a new AI model named Mythos has made the job of finding those weaknesses faster and cheaper than before. Mythos is designed to hunt for software flaws automatically, effectively doing in minutes what a skilled human researcher might take days to complete.
Oracle's response was to tear up its old patching schedule. Until this year, the company released security fixes four times a year. Starting in May, it switched to monthly releases. The first batch under that new schedule patched 35 vulnerabilities.
What does the new tool actually do?
Database Security Central gives a security team one dashboard rather than several. From that single screen, staff can see whether their database settings have drifted away from what the policy says they should be, a problem called configuration drift that tends to open quiet gaps attackers walk through later.
The tool also flags accounts with elevated privileges, meaning user accounts that have more access to data than the job actually requires. That matters because attackers who steal one of those accounts gain far more reach inside the organisation than if they had stolen a standard account.
Beyond user access, Security Central watches how sensitive data is being read and copied, collects the audit records that regulators often demand as proof of proper oversight, and enforces security policies centrally so that individual database teams cannot accidentally (or deliberately) deviate from the company standard.
Should customers be worried right now?
Yes, with caveats. The threat to Oracle databases is real, and the company's own decision to accelerate patching is a clear signal that it considers the risk elevated. At the same time, Database Security Central is a monitoring and policy tool, not a patch. It helps organisations see problems; fixing those problems still requires applying the actual updates Oracle releases each month.
For anyone whose employer runs Oracle databases, the practical step is straightforward: ask your IT team whether the May and subsequent monthly patches have been applied. If they have not, that gap is the more urgent concern.
Oracle says Security Central will be free until 28 February 2027. The tool was first reported by CSO Online.
| Item | Detail |
|---|---|
| Tool name | Oracle Database Security Central |
| Cost | Free until 28 February 2027 |
| Old patch frequency | Quarterly |
| New patch frequency | Monthly (from May 2025) |
| Flaws fixed in first monthly batch | 35 vulnerabilities |



