I'm willing to accept Suzanne's assertion that it is valid, but ...
I agree with Schyler, this is an unacceptable change.
It looks like typical malware! It is GOOD that many users have been questioning it! It is BAD that more have not!
For the first time after 4 years the users are expected to provide input into a click-to-(not)run update. It has not been done before. It is contrary to all explanations I have seen of how update CTR is supposed to work. How can it be passed off as "legitimate"?
How can users KNOW that it is legitimate?