Oracle Releases Free Database Security Tool Amid Growing Pressure From AI-Powered Bug Hunters
Oracle Database Security Central gives organisations a single place to spot risky database settings and unusual access patterns. It's free until February 2027, though the window that prompted its creation is already closing.

Key points
- Oracle released a free tool called Database Security Central to help organisations monitor and protect their database environments.
- The tool is available at no charge until 28 February 2027.
- Oracle switched from quarterly to monthly security patches in May after an AI model called Mythos began hunting for software flaws at speed.
- The first monthly patch batch fixed 35 vulnerabilities, meaning flaws attackers could exploit to break in or cause damage.
- Oracle databases are being actively targeted through known weaknesses in the software.
Oracle, one of the world's largest makers of database software, the programs companies use to store their most sensitive information, has released a new security tool and is giving it away free for roughly two years. The timing isn't a coincidence.
What pushed Oracle to act?
Attackers are going after known weaknesses in Oracle's database products, and an AI model named Mythos has made finding those weaknesses faster and cheaper. Mythos hunts for software flaws automatically, doing in minutes what a skilled researcher might take days to complete. We first covered Mythos on 28 May 2026, and our 29 July story found that vendors were pitching tools like it as the answer while defenders were still catching up.
Oracle's response was to tear up its patching schedule. Until this year, security fixes came four times a year. Starting in May, the company switched to monthly releases. The first batch patched 35 vulnerabilities.
What does the new tool actually do?
Database Security Central gives a security team one dashboard rather than several. From that single screen, staff can see whether their database settings have drifted from policy, a problem called configuration drift that opens quiet gaps attackers walk through later.
The tool also flags accounts with elevated privileges, meaning accounts with more access than the job actually requires. That matters because attackers who steal one of those accounts gain far more reach inside an organisation. Beyond access, Security Central watches how sensitive data is being read and copied, collects the audit records regulators demand as proof of proper oversight, and enforces security policies centrally so individual database teams can't accidentally deviate from the company standard.
Should customers be worried right now?
Yes, with caveats. The threat is real, and Oracle's decision to accelerate patching is a clear signal it considers the risk elevated. Our 5 August story documented one attack technique where intruders ran commands, stole password data and browsed files from inside an Oracle database itself after breaking in through a sloppy search box. That's the kind of exposure Security Central is designed to surface before someone else finds it first.
Security Central is a monitoring and policy tool, not a patch. It helps organisations see problems; fixing them still requires applying Oracle's monthly updates. For anyone whose employer runs Oracle databases, the practical question is whether the May and subsequent monthly patches have actually been applied. If they haven't, that gap is the more urgent concern.
Oracle says Security Central will be free until 28 February 2027. The tool was first reported by CSO Online.
| Item | Detail |
|---|---|
| Tool name | Oracle Database Security Central |
| Cost | Free until 28 February 2027 |
| Old patch frequency | Quarterly |
| New patch frequency | Monthly (from May 2025) |
| Flaws fixed in first monthly batch | 35 vulnerabilities |



