Patch your databases against AI-enabled cybersecurity threats

I guess you all read the announcements and predictions over the past weeks. New AI models and improvements to existing models may allow to find security issues in existing software much quicker. While this sounds alarming on one side (yes, it does), it also enables software vendors to secure their software. But in order to benefit from it, you must patch your databases against AI-enabled cybersecurity threats.

Patch your databases against AI-enabled cybersecurity threats

Photo by Scott Webb on Unsplash

Read the official announcements

At first, please read the official announcements released here:

In essence:

“[..] Oracle has access to leading frontier AI models, including Anthropic’s Claude Mythos Preview and OpenAI’s most capable models through Trusted Access for Cyber, and we are extending our capabilities with these models to improve how quickly and effectively vulnerabilities are identified.[..]”.

 

What does this mean for you?

Well, you guesses it already: You must patch. On a regular basis. And of course, not only your databases but also your OS, your apps, your clients. Regular means: At least quarterly, if not monthly. This will be a challenge for some of you, I know. But before you panic, we may have some relief, at least for the database.

  1. Upgrade to either Oracle Database 19c or Oracle AI Database 26ai

    When we ask in workshops who’s on older database releases, we still see many hands. In some countries it seems to be a tradition to stay on a database release which had been published over a decade ago. Frustratingly enough, this often applies to the most important environments. Telco billing, core banking, ATM machines, chip production, hospital environments, etc.Scary, isn’t it? I wrote about it 8 years ago – and it still is a massive problem.The good news: Upgrades never were easier. If you haven’t started, you will find a wealth of information on my team’s blogs. But you need to start now.

  2. Move to the cloud, and especially Oracle Autonomous AI Database

    When you have environments you really can’t keep up to date, especially with security patching, or where you have no resources to take care on, then consider moving them to Oracle Autonomous AI Database? Why could this be your savior? ADB gets patches on a regular basis with the most important fixes, and especially security fixes. This of course applies to Oracle Autonomous AI Lakehouse as well.Since we are the migration experts, we have the right tools. Contact us, we can help you lifting your databases quickly into ADB. If you want, even unattended. Give it a try at least – you’ll be positively surprised. And it will take away the burden of regular patching fire drills from your table.

  3. Patch, patch, patch

    I can write this easily. But I know how challenging this is. When you operate a group of Exadatas, then some stand-alone systems in addition, maybe some leftovers from over a decade ago, you can’t just say: “Oh, Wednesday, that’s patching day. Let’s do it now!” since this requires preparation, testing, sometimes even outages, downtimes. There are freeze periods, important events, super-sales, holidays. I know, it isn’t easy. But we can help you.AutoUpgrade allows you to quickly find the patches, download them to a staging server, then build the home on the target servers and patch your databases to the higher patch level. Fully unattended if you want. Scripted. Automated. Watch our Virtual Classroom Seminars #21, #27 and (when you are on MS Windows) #28.And of course, it does this at no extra license cost. Everyone has AutoUpgrade on disk already, refresh it with the newest version from oracle.com, and get started within minutes.

  4. Stop trusting others

    There is one important topic with patching: You must have access to our Support portal in order to be able to download the patches. Therefore, don’t trust vendors who promise to secure your database with a sort-of-firewall, or know everything already. Or even re-engineer our security fixes. While the latter wouldn’t be legal, none of them will be able to keep up with what Oracle is able to release. If you pay attention to security, then you will patch regularly. Which you can do either in the cloud or by downloading the necessary patches from My Oracle Support, and applying them right away.Don’t believe awesome marketing stories – and guess what, I ranted about this a few years ago as well in Virtual Patching – the biggest nonsense I’ve ever heard about. Believing always feels good – but it doesn’t secure your database.

 

Other changes which may affect you

As you already could read in Accelerating Vulnerability Detection and Response at Oracle, there may be monthly CSPUs available from May onward. Whether we repurpose the MRPs, or whether there will be another vehicle, I don’t know:

Oracle is expanding how security fixes are delivered to customers with a monthly Critical Security Patch Update (CSPU), starting in May 2026. CSPUs provide targeted fixes for critical security issues, allowing customers to address high-priority vulnerabilities without waiting for the next quarterly release. Each CSPU is smaller and more focused, making it easier to apply critical fixes quickly. Quarterly Critical Patch Updates will continue to include all fixes released in prior CSPUs. 

Well, and this concept may sound familiar, right? We’ve had CPUs a longer while back in conjunction with PSUs and then BPs. But these new ones will be released monthly, and let us wait together for the amount of content they will include.

But you should be positively aware that MRPs (Monthly Recommended Patches) are available already on Linux for Oracle Database 19c, and those contain security fixes already on a monthly cadence.

 

Password Protection for older RUs

Another change you may see soon (or, according to several customers: already) is the password-protection of older Release Updates (RUs). Some of you have gone through this exercise before with the 19.29 Release Update which is only available when you open an SR and get the download password from Oracle Support. This may be the norm soon when you plan to download an older RU.

Now, it seems to be in-place already, at least for RUs before 19.30, i.e. 19.29, 19.28 and below.

Password-protection for the 19.28 Release Update – you need to open an SR to get the password

If you can’t follow this pattern of applying always the newest directly, then this may be helpful:
Use AutoUpgrade to download your patches and patch bundles on a regular basis, and store them in your own repository folder. You then can install either the newest (which is the standard in AutoUpgrade), or direct AutoUpgrade to install an older RU from this folder. But let me be very clear here: You should always and with no doubt install and use the newest RU.

 

Summary

We live in interesting times. Every day seems to being a new challenge, something quite unexpected, and something which sound like impossible fiction a year ago. You can’t stop that, I can’t stop it either. Be we need to adept to it. So, for you, task #1 is to upgrade to 19c and 26ai where you haven’t done already. Watch your clients, ask us if you need help or advice.

Then start setting up your automated patching with AutoUpgrade right away. Of course, you can use also FPP or the OEM package if you are licensed for either one. But do something now, don’t sit it out.

Take this serious – I didn’t write this to scare you. It is real (unfortunately).

 

Further Links and Information

–Mike