HiddenMerit Daily · Issue 12

📊 HiddenMerit Daily · Issue 12

Focus on Database Frontiers, Practical Insights for DBAs May 7, 2026 | 5 Selected Global Breaking News

01|AI Security Microscope Strikes Again: 20‑Year‑Old RCE Flaw Exposed, 80% of Cloud PostgreSQL Directly Exposed

On May 4, Wiz’s AI‑powered security analysis tool Xint Code, during the ZeroDay.Cloud security event, uncovered a heap buffer overflow vulnerability (CVE-2026-2005) that had lain dormant in the PostgreSQL pgcrypto extension for two decades, as well as a still‑widespread JSON schema validation flaw in MariaDB (CVE-2026-32710). These vulnerabilities have existed since pgcrypto was first contributed in 2005. Affected PostgreSQL instances must be upgraded immediately to patched versions such as v18.2, v17.8, etc. Further analysis by Wiz found that among cloud environments running PostgreSQL, 80% are deployed, and of those, 45% are directly exposed to the internet.

· DBA Perspective · Immediate inventory of two high‑risk indicators: First, check production environments for pgcrypto extension loading and identify PostgreSQL instances directly exposed to the internet. Second, urgently review user creation permissions and establish a strict approval process for extension creation. · Beware of cloud network exposure risks: 45% of cloud PG instances exposed to the internet is a devastating risk. You must scan forward‑facing subnets, enforce timely patching, and correct misconfigured border firewall policies. · AI‑powered vulnerability discovery is the new paradigm: Security defenses must shift left. Databases containing sensitive data should proactively use AI security tools for deep scanning. · CTO Perspective · Automated security baselines are a must: Mandate the deployment of server‑side firewalls, cloud security groups, and automated vulnerability scanning systems. Do not rely on developer security awareness to keep databases safe. · Incentivise proactive security defense mechanisms: Organise regular internal “red‑vs‑blue” exercises, bug bounties, and other activities to actively improve the robustness of mature components. · Investor Perspective · The AI‑driven vulnerability discovery sector is heating up: Xint Code uncovered three major new vulnerabilities in enterprise software in a single event, demonstrating the huge potential of AI security tools. The trend of enterprise security budgets shifting toward AI‑powered risk control is now a certainty. · A new investment window opens in open‑source foundational software compliance: Even PostgreSQL, battle‑tested for a decade, has been found to have a 20‑year‑old low‑level flaw. Market demand for active security scanning services and security audit compliance tools will rapidly accelerate.

02|GDS Holdings and Huawei Sign Strategic Agreement to Jointly Deliver Next‑Gen AI Computing Centers with GaussDB

GDS Holdings recently announced a strategic agreement with Huawei to collaborate deeply on Huawei’s self‑developed high‑performance database GaussDB, accelerating the joint delivery and deployment of next‑generation AI computing centers. The agreement adopts a brand‑new model of “technology integration + resource co‑construction”, combining self‑operated data centers with GaussDB database software capabilities to provide high‑availability, elastically scalable data infrastructure for key industries such as finance, government, and autonomous driving. According to disclosed information, GaussDB meets the Level 4 requirements of the “Information Security Technology – Baseline for Classified Protection of Information Systems” in terms of same‑city dual‑cluster RPO=0 financial‑grade high availability, multi‑city multi‑site active‑active disaster recovery, and TPC‑C performance benchmarks. Its storage‑compute separation architecture supports second‑level online elastic scaling and is deeply integrated with the GaussDB data lifecycle management platform.

· DBA Perspective · The transition toward a “hyper‑converged role” for DBAs and operations teams is accelerating: Moving from pure data operations to cluster planning and elastic resource scheduling requires increased focus on advanced skills such as storage‑compute separation architecture and multi‑cluster disaster recovery. · Pay close attention to GaussDB’s high availability and AI‑powered self‑monitoring features: When GaussDB, combined with AI computing centers, becomes a mainstream delivery option, DBAs with this expertise will gain a strong foothold in the Xinchuang market. · AI computing centers challenge integrated digital infrastructure operations: Tightly coupled data center and database software/hardware design will test DBAs’ system engineering coordination abilities. · CTO Perspective · The AI computing center delivery model validates a standardised “national team” approach: The GDS‑Huawei co‑packaging strategy will reduce the huge effort small and medium‑sized enterprises face when selecting data center locations and deploying databases. · Domestic databases’ ability to handle complex computing loads becomes a key evaluation criterion: Industries like finance and autonomous driving have stringent requirements for high availability and synchronous disaster recovery; architecture choices must repeatedly verify the stack’s carrying capacity. This strategic agreement will serve as a benchmark for database selection. · Investor Perspective · The heat in intelligent computing infrastructure flows to GaussDB: The strategic agreement directly benefits third‑party service providers in the Huawei Cloud ecosystem. Related IT service providers and system integrators will see significantly improved contract acquisition rates in the government and autonomous driving sectors. · The “data center + domestic database” packaged strategy opens a new valuation logic: For GDS Holdings, long‑term hosting contracts will gain technical reputational benefits from Huawei’s intelligent computing brand.

03|MySQL 8.0 EOL Just Landed, Community Protests Oracle’s “Lack of Sincerity”; Popularity Sees Largest Single‑Week Drop in a Decade

MySQL 8.0 reached its scheduled EOL on April 30, with 8.0.46 becoming the final release of the 8.x series. However, complaints from the open‑source community have surged in recent days. Multiple active developers and enterprises have launched protests on social media, arguing that Oracle’s actual delegation of community authority has fallen far short of expectations. More than half of the new features, such as the Hypergraph Optimizer and full‑DML JSON Duality Views, require high‑end hardware to achieve 30%–50% performance gains, leaving ordinary developers unable to experience tangible improvements. DB-Engines popularity data shows that MySQL experienced its largest single‑week drop in nearly a decade in May 2026, with user satisfaction falling to a 24‑month low.

· DBA Perspective · Recommend targeting 8.4 LTS for upgrade decisions: If you are currently evaluating patch upgrades, based on reliability and long‑term support considerations, prioritise upgrading to 8.4 LTS rather than 9.7 LTS. · The new optimiser still needs grey‑scale validation: The Hypergraph Optimiser has high hardware requirements; fully stress‑test it in a staging environment before enabling it in production. · The shifting power dynamics in the MySQL ecosystem reflect community pushback: If the independent MySQL Foundation is formally established with support from key member companies, DBAs should closely monitor how governance changes affect the technical roadmap. · CTO Perspective · Open‑source ecosystem governance risk becomes a CTO burden: Oracle’s lack of community trust and substantive investment may lead to the loss of enterprise edition users and accelerate migration to MariaDB and PostgreSQL. You should proactively plan your dependency landscape for the next 3‑5 years. · 9.7 LTS’s “high‑end hardware for high returns” approach splits developer benefit perception: If you plan to adopt 9.7 LTS, you must factor hardware cost budgets and business benefit contingency plans into your planning. · Investor Perspective · The battle over the independent MySQL Foundation proposal is entering a critical phase: If Oracle fails to provide substantial concessions, the independent foundation and cloud‑native alternative projects will likely launch more aggressive diversion efforts in the second half of 2026. · Watch for structural revenue pressure in Oracle’s financial reports and a year‑over‑year decline in MySQL Enterprise Edition paid users.

04|GDS‑Huawei Strategic Agreement – Plus Another Major News: Vertica Launches AI Lakehouse to Empower Data Management

Following the above strategic agreement, Vertica, at its annual user conference Unify 2026 on May 5, officially launched an open AI Lakehouse platform. It provides a new RapidServing fast‑access engine supporting real‑time AI inference pipelines for both structured and unstructured data. The platform natively integrates with metadata services from AWS, Azure, and Google Cloud, features over 1,000 pre‑trained feature models and an automated vectorisation pipeline, and can automatically assemble raw text, images, and logs into a large‑model knowledge base cache. Its columnar execution engine and pure SQL interface allow PyTorch and TensorFlow models to be used directly without offline export, enabling near‑real‑time progressive loading. All metadata changes are handled through a unified control plane. The release also incorporates the open‑source DB‑GPT framework, enabling business users to flexibly perform large‑model fine‑tuning and RAG experimentation within the lakehouse, aiming to unify AI workloads with high‑concurrency encrypted queries.

· DBA Perspective · Lakehouse architecture is replacing the ETL era: DBAs will free up substantial effort from endless data movement and cleaning, shifting toward cross‑platform lakehouse join tuning. · “AI as SQL” self‑service data access capability becomes a watershed: In the next six months, automated incremental feature engineering and vectorisation in lakehouses will significantly lower the cost of manually building and assembling AI data pipelines. · Vertica’s columnar execution engine directly hosting models indicates that AI‑native databases are moving toward native SQL invocation. DBAs may need to collaborate more closely with machine learning engineers and feature management teams. · CTO Perspective · The modern data stack faces “platform silo” risks: A lakehouse that is tied to a specific public cloud’s metadata service may still introduce multi‑cloud fragmentation. Decision‑makers should guard against secondary lock‑in and ensure platform openness when planning roadmaps. · AI scale‑up pressure will shift from traditional OLAP to lakehouses: Integrating RAG, model fine‑tuning, and vector search enables fast AI value capture by the business, but query latency curves and the risk of uncontrolled costs must be closely monitored. · Investor Perspective · The open lakehouse sector is expanding into the AI inference layer: Vertica’s move shows that traditional OLAP vendors aim to capture entry traffic to AI infrastructure via engines and pre‑trained models. Pay attention to startups with similar strategies that have built a meaningful competitive edge in supply chain management. · Code debt management in MAD (Machine Learning + AI + Data) environments remains a huge commercial gap: Service providers that can upgrade legacy data platforms and simultaneously meet next‑generation parallel workload demands will enjoy strong renewal orders.

05|Frequent Capital Moves in Domestic Databases: Dameng Adjusts Executive Team, OceanBase 4.2.4 LTS Released

On May 6, Dameng issued an announcement of executive team adjustments. Against the backdrop of accelerating Xinchuang market demand, the company has strengthened its customer‑facing teams for finance, energy, and telecoms, preparing for a major push to replace large‑scale core systems in the second half of the year. On May 7, OceanBase Community Edition announced the release of version 4.2.4 LTS, with significant enhancements to columnar real‑time analytics, multi‑tenant configuration management, and the performance boundaries of the CASCADE distributed framework. After code merges into the main repository, high‑frequency iteration has fully resumed. At the same time, the new Oracle 23ai RUs continue to be released on a stable quarterly cadence.

· DBA Perspective · Executive adjustments signal deeper core system replacement with domestic databases: Leadership changes often imply accelerated product roadmaps and sales targets. DBAs in finance and energy sectors can proactively engage with Dameng’s training resources. · OceanBase 4.2.4 LTS improves stability of mixed columnar analytics workloads: DBAs handling HTAP tasks can use this release to upgrade their internal POC with clustered framework capabilities. · Oracle 23ai’s high‑frequency RUs force DBAs to change their operational mindset: Adapting to quarterly RUs means change management and patching processes must become more systematic and thorough. · CTO Perspective · Dameng’s refreshed go‑to‑market team signals full‑scale finance and energy Xinchuang deployment: Request vendors to conduct more complex no‑outage switchover drills and proactively ask for POC environments to test maturity. · OceanBase 4.2.4 LTS open‑source deployment expands possibilities: Enterprises can now test the carrying capacity of domestic distributed architecture in large‑data‑volume, cross‑cloud elastic scenarios. · Investor Perspective · Dameng’s executive reshuffle is a signal of accelerating market share capture: In the context of deepening Xinchuang replacement, being the first to secure national‑level core system share is the most critical moat. · OceanBase’s LTS release may accelerate user growth: 4.2.4 LTS sets a new industry benchmark in stability, multi‑tenant performance, and DBA friendliness. Watching its overseas customer signing metrics and public cloud penetration trends will be important leading indicators to identify value opportunities.

[quads id="805"]

📅 Recent Database Hot Topics Recap

Date Event Core Highlights May 4 AI security tool Xint Code uncovers 20‑year pgcrypto RCE and other major flaws 20‑year‑old vulnerabilities exposed; 45% of cloud PG instances internet‑facing May 5 Vertica Unify 2026 launches AI Lakehouse Open lakehouse with direct pre‑trained model integration; 1,000+ built‑in feature models May 6 Dameng adjusts executive team Strengthens customer teams for finance, energy, telecoms May 6 MySQL popularity sees decade‑worst weekly drop Community protests Oracle’s lack of openness; migration accelerates May 7 OceanBase 4.2.4 LTS officially released Enhanced columnar analytics + multi‑tenant CASCADE framework performance May 7 GDS‑Huawei GaussDB AI computing center strategic agreement signed “National team” model packages data center + database for unified delivery May 29 Tencent Cloud “Database + AI” product launch Domestic AI‑In‑Database roadmap culminates

📌 Issue Summary

News Core Keywords DBA Actions CTO/Decision‑Maker Focus Investor Perspective AI security tool finds 20‑year PG/MariaDB RCE 20‑year flaws, heap overflow, Xint Code’s black‑hat disclosure Urgently audit pgcrypto configs, lock down 45% cloud‑exposed assets; upgrade to patched versions; enforce extension approval system Deploy security groups & automated vulnerability scanning; run regular red‑vs‑blue exercises and bug bounties; shift security left to architecture design AI‑powered vulnerability discovery sector heats up rapidly; open‑source security compliance audits will be tied to enterprise procurement budgets GDS‑Huawei AI computing center strategic agreement Huawei GaussDB, financial‑grade active‑active multi‑site, co‑delivery model Learn GaussDB’s storage‑compute separation and elastic scaling; accelerate DBA + data center hardware/software coordination Domestic DB + data center packaged delivery model is standardising; a benchmark for core Xinchuang replacement is born Hosting contracts gain significant technical reputational lift; Huawei Cloud ecosystem service providers can expect strong order pipelines MySQL popularity plunges + community protests 8.0 EOL migration pain; Hypergraph optimiser requires high‑end hardware Lock upgrade path to 8.4 LTS to reduce uncertainty; grey‑test Hypergraph with cost accounting; closely watch independent MySQL Foundation progress Erosion of community trust and loss of paying enterprise customers are key variables; new hardware acceleration makes 9.7 LTS an expensive bet Foundation battle intensifies, Oracle faces structural revenue dilution; multi‑cloud alternative projects will divert enterprise budgets AI Lakehouse unified lakehouse platform launched Vertica open AI inference pipeline, SQL+PyTorch seamless usage Learn lakehouse federated querying and vector pipeline construction; complete batch‑stream integration platform migration early If lakehouse is locked to a public cloud’s metadata service, secondary barriers form; AI cost optimisation should target unified metadata management Battle for AI infrastructure ingress intensifies; upgrading MAD environments becomes a new commercial gap Dameng executive changes + OceanBase 4.2.4 LTS Finance/energy Xinchuang accelerates; leadership reshuffle strengthens top‑tier markets Proactively request Dameng trial/training resources; validate OceanBase columnar + multi‑tenant POC effectiveness Complete no‑outage switchover drills and domestic replacement selection loop; test domestic distributed limits in cross‑cloud environments LTS version will accelerate user growth; overseas signings and public cloud penetration are leading indicators to watch

HiddenMerit Team Production Slogan: 绩优隐于内,金石启新程 | Hidden deep. Merit bold. Forge ahead.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top