HiddenMerit Morning Post · Issue 69

📊 HiddenMerit Morning Post · Issue 69

Focus on Database Frontiers, Practical Insights for DBAs August 6, 2026 | 5 Selected Global Breaking News

01|Attackers Exploit Oracle SQL Injection Vulnerability to Deploy Khunt Post‑Exploitation Toolkit

On August 6, security researchers disclosed that attackers successfully exploited an SQL injection vulnerability in Oracle databases to install and run the Khunt post‑exploitation toolkit within the database environment. This attack vector enables attackers to use compromised databases as a springboard to establish footholds and move laterally within enterprise networks.

What makes the Khunt toolkit particularly concerning is that it runs inside the database itself – extending the attacker’s attack surface and persistence capabilities, allowing direct post‑exploitation operations from the database system. This demonstrates that the threat of SQL injection vulnerabilities has evolved beyond mere data theft to potentially enabling full‑scale enterprise network infiltration.

  • DBA Perspective: This event serves as another wake‑up call – SQL injection is no longer just a “data leakage” problem, but could become the “front door” for attackers to enter enterprise internal networks. When attackers can deploy post‑exploitation tools inside the database, the database has become the starting point, not the endpoint, of an attack. DBAs should adopt more aggressive defense strategies: first, enforce strict input validation and parameterised queries on Oracle databases; second, monitor abnormal processes and system command execution behaviour within the database; third, follow the principle of least privilege to limit database account permissions.

02|Google Launches Two AI Database Agents: Natural Language Takes Over Full Database Lifecycle Management

On August 5, Google officially launched two AI database agents – Database Onboarding Agent and Database Observability Agent – marking the entry of cloud database management into a new “natural language‑driven” era.

Onboarding Agent: Users simply describe workload requirements in natural language (performance needs, data scale, data types, etc.), and the agent recommends the best‑matched managed database service (AlloyDB, Cloud SQL, Spanner, Bigtable, etc.) and generates complete configuration and deployment commands. The agent also understands technical metrics such as IOPS, latency thresholds, and replication lag.

Observability Agent: Focused on daily operations, integrating telemetry data from Database Insights, Cloud Monitoring, Cloud Logging, and Cloud Trace. Users can ask natural language questions like “Which databases had the highest CPU usage in the last hour?” or “Why is there lock contention?” The system automatically identifies root causes and provides remediation recommendations, with automatic execution after approval in some scenarios. The observability agent covers Google’s full range of managed database products, including AlloyDB, Bigtable, Cloud SQL, Spanner, Firestore, and Memorystore.

Google describes this capability as “giving developers a virtual DBA” – accessible through Gemini Cloud Assist, chat interfaces, CLI, console, or even IDEs.

  • DBA Perspective: Google’s AI database agents are another milestone in “intelligent operations” for cloud databases. Unlike Tencent Cloud’s DatabaseClaw approach of “distilling hundreds of thousands of DBA work orders into Skills,” Google has chosen a technological path of “natural language + full‑stack telemetry fusion.” For DBAs, this means routine monitoring, slow query analysis, capacity assessment, and other repetitive tasks will gradually be replaced by AI agents. The DBA role is evolving from “manual operations” to “AI agent policy manager” – defining AI operational boundaries, auditing execution traces, and triggering circuit breakers during anomalies. The observability agent’s root cause analysis capability is the core indicator of whether AI truly “understands” the operational state of databases.

03|GBASE and Hygon Launch Customised Database: Domestic Compute + Database “Turnkey Solution”

On August 5, GBASE and Hygon Information jointly launched the GBASE Hygon Customised Database, providing an integrated turnkey solution combining domestic compute power and database.

Performance Data: Leveraging the collaborative advantages of the Tianjin Xinchuang industry cluster, the two parties conducted deep optimisation and adaptation. Testing with standard datasets showed that the overall performance of the Hygon processor in the customised database improved by more than 2 times compared to the general‑purpose version. Additionally, the hardware encryption built into Hygon processors can replace traditional software encryption, reducing memory usage and achieving encryption without performance degradation, making database operation smoother.

GBASE has deep roots in the domestic database space: according to Modb data, GBASE ranked fourth among domestic independent commercial databases in the May 2026 China Database Popularity Ranking. Its GBase 8c (AI‑native database) and GBase 8a (analytical database) have achieved large‑scale deployment in finance, government, and other industries. GBASE and Hygon are both located in Tianjin Binhai Hi‑Tech Zone, and this customised database represents a milestone in the collaborative development of the local Xinchuang industry chain.

  • DBA Perspective: The deep collaboration between GBASE and Hygon is a milestone event in the Xinchuang ecosystem, moving from “compatibility lists” to “performance optimisation.” The more than 2‑fold performance improvement is not merely compatibility validation, but deep collaborative optimisation between chip instruction sets and database kernels. For DBAs, this means that hardware selection in Xinchuang projects is no longer just about “whether it’s compatible,” but a quantitative assessment of “how well it performs.” The hardware encryption feature’s memory‑saving design also reminds DBAs that when evaluating domestic databases, they need to pay attention to the performance impact of hardware‑software collaborative encryption solutions.

04|ClickHouse Labs Established: CMU Professor Andy Pavlo Appointed VP of Research

On August 4, open‑source real‑time analytics database ClickHouse announced the establishment of ClickHouse Labs and appointed Andy Pavlo, Associate Professor of Computer Science at Carnegie Mellon University (CMU) and head of the CMU Database Research Group, as Vice President of Research.

Pavlo is a landmark figure in the database academic community, having received the IEEE TCDE Database Education Award, the VLDB Early Career Award, the NSF CAREER Award, the Sloan Research Fellowship, and the ACM SIGMOD Jim Gray Best Paper Award. ClickHouse Labs will focus on foundational research in database architecture, query processing, system performance, and infrastructure, with research outcomes benefiting both the ClickHouse and PostgreSQL open‑source projects.

Pavlo stated: “The most exciting database research doesn’t just put new ideas into papers, but proves their feasibility by building and testing real systems.” ClickHouse CTO Alexey Milovidov said: “ClickHouse Labs, under Andy’s leadership, will lead our investment in foundational research, helping shape the future of ClickHouse and the broader database industry.”

[quads id="805"]

Pavlo previously co‑founded OtterTune, which applied machine learning to database optimisation. His dual background in academia and business means ClickHouse is likely to accelerate in the direction of AI‑driven autonomous databases. ClickHouse users include Sony, Tesla, Anthropic, Lyft, and Instacart.

  • DBA Perspective: Andy Pavlo’s appointment is another significant milestone following his co‑founding of OtterTune. For DBAs, this event means: the boundaries between academia and industry are further dissolving – CMU’s academic expertise will directly translate into production‑grade optimisations for ClickHouse; open‑source databases are building trust through “open research” – research outcomes will be publicly released, allowing external developers to review, test, and extend them. Pavlo has explicitly stated he will research “how DBMS adapt to AI and agent technologies,” including how databases can better support agents, and how agents can automate and improve DBMS development itself. DBAs should pay attention to ClickHouse Labs’ subsequent research publications – they are important references for assessing ClickHouse’s long‑term technology direction.

05|NineYou Database and Peking University Joint Project Passes Technology Assessment: Dual‑Distributed Architecture Reaches World‑Leading Level

On August 5, the joint project “Key Technologies and Applications of Trusted Multi‑Modal AI Data Infrastructure” by Shenzhen NineYou Database Co., Ltd. and Peking University successfully passed a technology achievement assessment. The expert panel was chaired by Zhang Jingzhong, an academician of the Chinese Academy of Sciences.

Core Technology Breakthroughs: The project addresses the strategic need for domestic replacement in critical sectors, with independent breakthroughs in key technologies including dual‑distributed architecture and intelligent routing for heterogeneous replicas, multi‑modal hyper‑convergence with cross‑modal strong consistency, and AI‑native security‑converged kernel architecture, forming a fully autonomous next‑generation hyper‑converged database solution.

Assessment Conclusion: The expert panel unanimously agreed that the achievement overall reaches the domestic leading level, with the dual‑distributed architecture and heterogeneous replica technologies reaching world‑leading level. The project has obtained 21 invention patents and 24 software copyrights, and participated in the development of 10 industry and group standards.

Implementation Progress: The achievement has been deployed at scale in key industries including finance, government, energy, maritime, and transportation, with full‑stack adaptation to the Xinchuang ecosystem including Kunpeng, Hygon, Kylin, and UnionTech.

  • DBA Perspective: The significance of NineYou Database’s technology assessment lies in the fact that domestic hyper‑converged databases have received academician‑level recognition for core technologies. The “dual‑distributed architecture” technology reaching world‑leading level means that domestic multi‑modal AI databases now have the technical confidence to benchmark against mainstream international products in distributed architecture design. For DBAs, this provides a reference benchmark for evaluating the technical maturity of multi‑modal databases in Xinchuang selection. NineYou Database has obtained 21 invention patents and 24 software copyrights, with large‑scale deployments across finance, government, energy, and other key industries – its technology path is worth evaluating in Xinchuang selection.

📚 SQL Little Knowledge Point

This Issue’s Knowledge Point: What is “Dual‑Distributed Architecture”?

“Dual‑distributed architecture” is a core technical concept proposed by NineYou Database in the “Trusted Multi‑Modal AI Data Infrastructure” project. In traditional distributed databases, after data is sharded, the sharding strategy is often “fixed” – once determined, subsequent scaling or adjustment becomes extremely costly.

Core Design of Dual‑Distributed Architecture:

Dimension Traditional Distributed Architecture Dual‑Distributed Architecture
Data Sharding Fixed sharding strategy Dual‑layer sharding, supports dynamic adjustment
Replica Routing Fixed replica strategy Intelligent routing, dynamically selects replicas based on load
Heterogeneous Adaptation Single engine Supports heterogeneous replicas, unified access to cross‑modal data
Elastic Scaling Scaling requires data redistribution Online scaling, business‑transparent

World‑Leading Technology Breakthrough: NineYou Database’s “dual‑distributed architecture and intelligent routing for heterogeneous replicas” technology was assessed by the expert panel as world‑leading, solving the industry challenges of fixed sharding in traditional distributed databases and inefficient access to multiple single‑modal databases.

HiddenMerit Team Production Slogan: 绩优隐于内,金石启新程 | Hidden deep. Merit bold. Forge ahead.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top