upgrade -y -o APT::Get::Show-Upgraded=true
The second line is changed from "dist-upgrade -d ...", because you don't want any automatic dist-upgrades. That might leave your server in a horrible state. Also, instead of only downloading (-d), you want it to install the upgrades as well. That's all and should help you keep up with security patches more easily.
Update: The updates seem to work fine! Tonight I got the first email that notified me of a successful security update.