We are receiving ATP alerts because our machines are trying to access Windows update at 209.197.3.8. They've been hitting that IP for months, but the alerts just started.
Is this a false positive?
Manually updated, let's see what happens...
I'm on 227043 an there are no more detections.
Ours went to 227044 and all is now quiet.