Hot take: having security tools isn't the same as having security.
If your scanning doesn't gate a release, it's not a control. It's a dashboard nobody checks.
This matters especially in SitecoreAI headless builds, where most of what you ship was written by someone else, not you. Each one is a trust decision you didn't consciously make.
Take the TanStack incident from May 2026. The attacker didn't need stolen credentials, they hijacked the build pipeline itself, published 84 malicious packages in under 6 minutes, and stole cloud keys from every machine that ran npm install. Schedule-based scanning doesn't save you from that.
If you're not sure your pipeline would have caught a compromised package before it hit production, this blog from our CTO Piers Matthews, is worth a few minutes of your time.
#DevSecOps#PipelineSecurity#SupplyChainSecurity#SitecoreAI#Dataweavers#Security#HeadlessCMS
Vibe coding is changing how fast software ships. That's a problem if your infrastructure wasn't built for it.
When you increase the velocity of code, you amplify everything that was already true about the platform underneath. The strong patterns scale. The gaps scale too.
Observability that was acceptable at a two-week release cadence becomes a liability at daily deployment. Security assumptions that held up under human-paced review get stress-tested fast when AI is generating production code at volume.
Our CEO, Ben Shapiro, wrote about the three infrastructure gaps that will make or break your AI-native DXP rollout. And why they're a lot cheaper to fix now than during a production incident.
dweav.rs/4v56SyE#VibeCoding#Headless#DXP#EnterpriseIT#AgenticAI#Dataweavers#HeadlessCMS
The Sitecore City Tour wrapped up its Chicago and Boston stops with standing room only at both, and after spending time in those rooms it is pretty clear why.
The DXP market has genuinely shifted. AI has moved past being a feature you bolt onto a platform and is becoming the operating model the whole thing runs on, which means the organisations treating this as a tech refresh cycle are going to find themselves a long way behind the ones treating it as a full business reinvention.
Leaders from United Airlines, Shure, SNHU and Michigan State got up on stage and talked honestly about what is working and what isn't, which is what made these rooms worth being in.
Jill Roberson pulled together what came through across both cities into a recap that is worth a read if you are thinking about where digital experience is heading next.
📍dweav.rs/43bjM1G
We're heading to Chicago!
Dataweavers is proud to be sponsoring the @Sitecore City Tour in Chicago at The Metropolitan Club, and we'd love to see you there!
This is a fantastic opportunity to explore how AI is reshaping digital experience and connect with some of the sharpest minds in the Sitecore ecosystem.
If you're a marketer or technologist thinking about what the next generation of digital experience looks like...this event was made for you!
Come find us on the day! We'd love to chat about how Dataweavers can help your team get the most out of your Sitecore investment.
dweav.rs/4d56M1W#Sitecore#SitecoreAI#Headless#EnterpriseHeadless#HeadlessDXP#Dataweavers#SitecoreCityTour
A trusted plugin changed hands on a public marketplace. Eight months later, hundreds of thousands of WordPress sites were quietly serving malicious content, with no way for site owners to know.
The plugin ecosystem is the attack surface. Here's what that means for enterprise teams →
dweav.rs/4uj2uev#WordPress#WebSecurity#CMS#SupplyChainRisk#DXP#HeadlessCMS#HeadlessDXP
If AI can't see you, your customers won't either.
Join Sitecore CMO Michelle Boockoff-Bajdek and Horizontal Digital's Ebin C. Ephrem to find out how to stay ahead.
Secure your spot: siteco.re/4sjI8Ak
Your headless Sitecore site passed every delivery checklist. It was live. Serving customers. Nothing was broken, but the browser had almost zero constraints on what it could load or execute.
"Working" and "secure" are not the same thing.
Here's what's actually breaking in headless security, and how to fix it →
#Sitecore#WebSecurity#Headless#CMS#AppSec#SitecoreAIdweav.rs/3QG9inV
🔥 Live at Opticon! 🔥 Dataweavers CTO, Piers Matthews, presenting TODAY at 1 PM in Theatre 2. Driving Innovation with Platform Ops Discover how automation simplifies CMS, boosts security, and drives innovation. Ready to level up? Let’s connect! @Optimizely#Opticon24
Ready to roll! Our Brisbane and New York teams have packed their bags along with their Dataweavers SWAG and are all set for next week to meet up with the Sitecore community at Symposium in Nashville 🎉
#SitecoreSYM#PowerToBuild#Symposium#DXP
Our Platform-as-a-Service automates and manages Sitecore DXP infrastructure, simplifying operational environments, creating the space for innovation and enabling teams to focus on delivering exceptional digital experiences.
Find out more: dataweavers.com/
It's officially Symposium season! Don't miss our theater session - "The Pathway to Composable with Platform Operations", with Dataweavers very own Chief Technology Officer Piers Matthews. He will be taking the stage 17th October at 1:00pm in the Solutions Pavillion. #SitecoreSym
It's officially Symposium season! If you've started planning, it's worthwhile putting our theater session on the agenda to learn about 'The Pathway to Composable with Platform Operations' with our CTO, Piers Matthews, taking the stage 15th Oct at 7:00pm. #SitecoreSYM
Transform your Sitecore XM Cloud with Dataweavers Platform Ops:
🚀 Faster, secure, & cost-efficient
🔄 Zero-downtime releases
🌎 Seamless global content sync
👨💻 24/7 support for your entire stack
Simplify your DXP today: dataweavers.com/products/sit…#Sitecore#PlatformOperations
Dataweavers Platform Operations deployed in Azure PaaS are purpose-built with modern platform engineering principles to automate repetitive tasks, streamline workflows, and ensure consistency.
dataweavers.com/platform-ope…
We’re excited to welcome Brian Yoo to Dataweavers as the new SDR Manager in our New York City office! 🎉
Brian says, "The small but powerful team is simply amazing. Every single person has bought into the vision of the founders."
Dataweavers Platform Operations approach allows your team to focus on innovation and future development while we handle both your traditional and composable environments.
Learn more: dataweavers.com
We've got you covered - whether its end-to-end management of your Sitecore environment, or a weekend on the green. 😄 ⛳
Thanks for the great photo Christian Bing-Capiraso 👏