Looking back through this entire thread it seems to me that it's likely this recent variation of this particular detection, which was dated Feb 02, has probably found a new method of manipulating the Edge browser's JavaScript in a way that allows it to trigger
such popups.
Since from other threads I see that a typical detection is simply for the flashplayer.hta file in the browser cache, it's still questionable whether any true malware is involved. In fact, as I recall the more typical operation of real-time detections by
Microsoft had been to completely ignore the cache, since in most cases these items were blocked by the security features in the browser itself.
So what I think we may be seeing here is the operation of a modified detection designed to head off this particular family or specific variant due to a deeper problem with whatever vulnerability within the browser it's exploiting to execute its payload.
In other words, exactly as Microsoft has always done with their antimalware products, they're using Defender to block the operation of a new type of malware exploitation until they can build, test and deploy the actual patch to the Edge code, possibly a
flaw in hta handling, that's truly causing the problem. This is what's causing the increase in "noise" for Defender, a drastic change from it's more typically quiet operation.
I say all of this due to the discussion of symptoms and apparent change in operation that Greg and others here have mentioned, while for others like myself there's been no change at all, since the attack vector of advertisements is something some of us have always
known and blocked as a workaround.
If I'm correct the timing of the last two variants of this detection on Feb 02, with the later addition of a PowerShell variant on Feb 14th, implies we may see an update released within the typical March Black Tuesday package that deals with this deeper
issue.
Rob
Furthering the above speculation, here's a possible candidate that may explain why these un-characteristic detections within the cache were added, as well as why the documentation for them seems so sparse.
Google discloses ‘high-severity’ exploit in Windows 10 before it’s patched