Find notable cyber news and cases, enriched with sources, timelines, and signals.

WSL Containers general availability adds Defender for Endpoint visibility and Intune controls

Security Tool/Service
First reported
Last updated
Happening score
H score 14
1 unique sources, 1 articles

Summary

Hide ▲

WSL Containers reached general availability, expanding Windows support for building and running Linux containers while adding enterprise security visibility and administrative control. The release now connects with Microsoft Defender for Endpoint and Microsoft Intune, letting defenders monitor container activity and restrict registry sources. It also adds a new wslc.exe CLI, a container.exe alias, and an API for Windows apps that need to manage containers programmatically.

Related Happenings

ValleyRAT malicious installer activity

Malware Activity
H score22 First: 02.09.2026 19:41 Last: 02.09.2026 19:41 Sources 1

About this happening: ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has a...

HoneyMyte PlugX campaign targeting Myanmar

Campaign
H score32 First: 14.08.2026 16:08 Last: 14.08.2026 16:08 Sources 1

About this happening: The HoneyMyte campaign targeting Myanmar now uses PlugX to deploy CoolClient and persistence steps that make post-compromise access harder to detect. The activity...

SprySOCKS Windows backdoor activity against government organizations

Malware Activity
H score23 First: 16.06.2026 12:00 Last: 16.06.2026 12:00 Sources 1

About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

Microsoft Defender RedSun LPE zero-day privilege-escalation flaw

Vulnerability
H score35 First: 16.04.2026 23:19 Last: 16.04.2026 23:19 Sources 1

About this happening: A public RedSun proof-of-concept exposed a Microsoft Defender local privilege escalation zero-day that can reach SYSTEM on Windows 10, Windows 11, and Wi...

Latest development: 17.04.2026 16:21

Huntress reports that threat actors are exploiting Microsoft Defender flaws, including RedSun, to gain elevated privileges on compromised systems, and says it isolated the affected organization to prevent further post-exploitation.

Timeline

  1. 30.09.2026 03:40 2 articles · 1h ago

    Microsoft makes WSL Containers generally available

    Initial Disclosure

    Microsoft made WSL Containers generally available for Windows Subsystem for Linux, adding the wslc.exe CLI, the container.exe alias, and a WSL Containers API for Windows apps to build, run, and deploy Linux containers on Windows. The release also integrates with Microsoft Defender for Endpoint for process, file, and network visibility inside containers, and Microsoft Intune can disable WSL Containers or restrict developers to approved container registries; VS Code Dev Containers, Aspire, and the VS Code Containers extension also support WSL Containers.

    Show sources