Storylines

Storylines

Storylines connect related signals across days and weeks so you can follow a narrative over time.

How to use: Scan → open one item → check evidence.

ScoreAttention velocity, not truth.MomentumAttention velocity, not truth.
Selection window 24hSelection window for ranking; freshness is shown by the Updated badge.2026-W12Evidence trails in app
Flagship sampleUnlocked today
CISA warns of active exploitation of critical Microsoft SharePoint vulnerability CVE-2026-20963
One free full-detail item per day. Source links included.
The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-20963.
+2 more sources
Storylines dashboard

Sorted by momentum. Use the chevron to expand a card. Use the action button for the full drawer.

No investment advice. Research signals and sources only. EarlyNarratives provides informational signals derived from public sources. It does not provide financial, legal, or tax advice.

Category
Top storylines split into product releases and broader narratives.
View mode
Reader mode keeps the list scanable with compact cards and minimal controls.
Filter matches title, tags, and tickers.
This week

Editorial picks from the weekly briefing.

Oracle patches critical unauthenticated remote code execution vulnerability in Identity Manager

Oracle has released a critical security update addressing CVE-2026-21992, a vulnerability in Oracle Identity Manager and Oracle Web Services Manager that allows remote code execution without authentication. The flaw carries a CVSS score of 9.8, indicating severe risk.

Updated 2d agoActive span 1d
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.3
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
3
PostsCount of items included in the signal cluster for this window.Learn more
3
Details
2 publishers3 posts2 platformsTop source 67%
Evidence: 2 primary
#3 of 56StructuralEmerging confirmation
Emerging confirmationLimited history
cveexploits
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
2
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
33%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
67%
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.48
Why now
  • The vulnerability has a high CVSS score of 9.8, indicating urgent risk.
  • Oracle has just released an official fix, making immediate action possible.
  • Exploitation could lead to significant security incidents if left unpatched.
Why it matters
  • The vulnerability allows remote code execution without authentication, posing a severe risk to affected systems.
  • Oracle Identity Manager and Web Services Manager are widely used enterprise products, increasing potential impact.
  • Prompt patching is critical to prevent exploitation and potential breaches.
Evidence
Evidence is syncing

Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131)

A critical vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) that Cisco disclosed and patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang, Amazon CISO and VP of Security Engineering CJ Moses revealed. “.

Updated 3d agoActive span 1d
Steady
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.2
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
3
PostsCount of items included in the signal cluster for this window.Learn more
3
Details
3 publishers3 posts1 platformsTop source 33%
Evidence: 3 primary
#2 of 56StructuralBroad confirmation
Broad confirmationFlat
securityHelp Net Security
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
3
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
33%
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.65
Evidence
Evidence is syncing

CVE-2026-20963 (SharePoint deserialization) hit the CISA KEV yesterday

Coverage centers on: Updated CISA exploited flaws list adds SharePoint, Zimbra bugs.

Updated 3d agoActive span 1d
Steady
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.4
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
3
PostsCount of items included in the signal cluster for this window.Learn more
3
Details
3 publishers3 posts2 platformsTop source 33%
Evidence: 2 primary
#1 of 56StructuralBroad confirmation
Broad confirmationFlat
securityUpdated Cisa
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
3
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
33%
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.71
Evidence
Evidence is syncing
Trending now

Latest storylines from the latest runs. Sorted by momentum.

Market chatter

Apple security advisory (AV26-248)

Serial number: AV26-248 Date: March 18, 2026 On March 17, 2026, Apple published a security update to address vulnerabilities in the following products: iOS – versions prior to 26.3.1 iPadOS – versions prior to 26.3.1 macOS – versions prior to 26.3.1 macOS – versions prior to 26.3.2 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates

Updated 4d agoActive span 23h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.1
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
8
PostsCount of items included in the signal cluster for this window.Learn more
8
Details
1 publishers8 postsTop source 100%
#3 of 20Chatter
Limited historyChatter
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
1
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
100%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.27

Apple Products: CVSS (Max): None

=========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2026.2560 APPLE-SA-03-17-2026-1 Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2 18 March 2026 =========================================================================== AUSCERT Security Bulletin Summary -------------------

Updated 3d agoActive span 1d
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.9
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
7
PostsCount of items included in the signal cluster for this window.Learn more
7
Details
7 publishers7 postsTop source 14%
#6 of 20Broad confirmation
Broad confirmationLimited history
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
7
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
14%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.81

US, Canada and Germany take down four large DDoS botnets

Experts warn that the botnet operators will likely regroup and come back stronger, armed with AI.

Updated 2d agoActive span 12h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.7
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
7
PostsCount of items included in the signal cluster for this window.Learn more
7
Details
7 publishers7 postsTop source 14%
#7 of 20Broad confirmation
Broad confirmationLimited history
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
7
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
14%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.79

New “Darksword” iOS exploit used in infostealer attack on iPhones

A new exploit kit for iOS devices and delivery framework dubbed "Darksword" has been used to steal a wide range of personal information, including data from cryptocurrency wallet app. [...]

Updated 2d agoActive span 2d
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
2.1
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
7
PostsCount of items included in the signal cluster for this window.Learn more
7
Details
7 publishers7 postsTop source 14%
#5 of 20Broad confirmation
Broad confirmationLimited history
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
7
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
14%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.88

Interlock Ransomware Exploited Cisco Firewall Flaw for Weeks

AWS Researchers Find an Interlock Server Laden With Tools Ransomware hackers exploited a flaw with a maximum vulnerability score in Cisco firewall management software weeks before the networking giant disclosed the vulnerability in early March. The group has focused extensively on critical infrastructure sectors in North America and Europe.

Updated 3d agoActive span 23h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.6
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
6
PostsCount of items included in the signal cluster for this window.Learn more
6
Details
6 publishers6 postsTop source 17%
#9 of 20Broad confirmation
Broad confirmationLimited history
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
6
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
17%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.79

Hackers Exploit Critical Langflow Bug in Just 20 Hours

Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day

Updated 2d agoActive span 12h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.5
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
4
PostsCount of items included in the signal cluster for this window.Learn more
4
Details
4 publishers4 postsTop source 25%
#13 of 20Broad confirmation
Broad confirmationLimited history
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
4
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
25%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.78
Market chatter

Marquis Data Breach Affects 672,000 Individuals

It was previously estimated that more than 1.6 million people may be affected by the Marquis data breach. The post Marquis Data Breach Affects 672,000 Individuals appeared first on SecurityWeek .

Updated 3d agoActive span 12h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.5
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
4
PostsCount of items included in the signal cluster for this window.Learn more
4
Details
3 publishers4 postsTop source 50%
#12 of 20Chatter
Limited historyChatter
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
3
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
50%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.63
Market chatter

New ‘Perseus’ Android malware checks user notes for secrets

A new Android malware called Perseus is checking user-curated notes to steal sensitive information, like passwords, recovery phrases, or financial data. [...]

Updated 3d agoActive span 12h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.4
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
4
PostsCount of items included in the signal cluster for this window.Learn more
4
Details
4 publishers4 postsTop source 25%
#14 of 20Chatter
Limited historyChatter
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
4
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
25%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.78
Market chatter

USN-8112-1: Linux kernel vulnerabilities

Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - MMC subsystem; - Network drivers; - USB Device Class drivers; - BTRFS file system; - HFS+ file system; - XFRM subsystem; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - Simplified Mand

Updated 47h agoActive span 11h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.2
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
4
PostsCount of items included in the signal cluster for this window.Learn more
4
Details
2 publishers4 postsTop source 50%
#17 of 20Chatter
Limited historyChatter
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
2
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
25%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
50%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.44
Market chatter

Unifi Security Advisory Bulletin 062

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-22557, CVE-2026-22558, Summary: A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account. CVSS v3.1 Severity and Metr

Updated 2d agoActive span 1d
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.2
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
4
PostsCount of items included in the signal cluster for this window.Learn more
4
Details
4 publishers4 postsTop source 25%
#16 of 20Chatter
Limited historyChatter
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
4
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
25%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
25%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.71

FBI links Signal phishing attacks to Russian intelligence services

The FBI has issued a public service announcement warning that Russian intelligence-linked threat actors are actively targeting users of encrypted messaging apps such as Signal and WhatsApp in phishing campaigns that have already compromised thousands of accounts. [...]

Updated 47h agoActive span 11h
Limited history
ScoreOverall signal strength in the selected window; higher means more evidence/consistency, not a prediction.Learn more
1.3
Momentum 24hChange in signal activity over the last 24 hours; higher means accelerating attention, not performance.Learn more
3
PostsCount of items included in the signal cluster for this window.Learn more
3
Details
3 publishers3 postsTop source 33%
#19 of 20Broad confirmation
Broad confirmationLimited history
OriginsDistinct origin sources contributing to this signal; higher means broader origin coverage.Learn more
3
Dup ratioShare of near-duplicate items in the cluster; higher can indicate repetition or amplification.Learn more
0%
Top origin sharePortion of items from the top origin; higher means more concentration.Learn more
33%
SourcesNumber of source types represented (e.g., news vs social).Learn more
0
Maturity scoreHeuristic confidence score derived from breadth and consistency indicators.Learn more
0.67
Unlock evidence trails

Unlock source trails, evidence timestamps, archive access, and workflow tools.