Microsoft has made WSL Containers generally available, enabling organizations to build, run, and deploy Linux containers directly through Windows Subsystem for Linux. The release adds the wslc.exe command-line utility, a container.exe alias, and APIs allowing native Windows applications to manage Linux containers. Operational capabilities include restart support, file copying, health checks, mounts, network-connection management, configurable storage, and event monitoring; it also integrates with VS Code Dev Containers and Aspire.
For enterprise governance, Microsoft Intune can enable or disable WSL Containers and limit image downloads to approved registries. Microsoft Defender for Endpoint's WSL plugin provides visibility into container processes, files, and network activity and correlates telemetry with the Windows host. Docker Compose compatibility is not yet available, but Microsoft is developing a planned wsl compose up capability, while also reporting up to twice-faster Windows-file access from Linux environments.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft announced WSL Containers' general availability, enabling Linux containers to be built, run, and deployed directly on Windows through WSL. The release includes the wslc.exe tool and native application APIs, operational container capabilities, Intune policy controls, and Defender for Endpoint visibility for container activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceblogs.windows.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.