> ## Content Index
> Fetch the complete content index at: https://www.freshfromcache.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Also this week: a false antivirus warning, an FTC lawsuit over Amazon's ad prices, and 19 browser add-ons gone bad
- URL: https://www.freshfromcache.com/also-this-week-2026-09-04/
- Published: 2026-09-04T11:00:00.000Z
- Updated: 2026-09-04T10:59:59.000Z
- Description: A Windows pop-up is wrong about your antivirus. The FTC says Amazon padded its ad prices. Nineteen browser add-ons turned on their users. Android 17 shuts a door scammers use.
- Author: Joel Folgner
- Tags: News

I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week.

## A Windows pop-up says your antivirus is off, and Microsoft says the pop-up is wrong

After a recent update to Microsoft Defender, Windows can put up a notice reading "Microsoft Defender Antivirus is turned off," with a prompt to tap or click to turn it back on. On August 28 Microsoft confirmed the notice is a bug. Its release-health page says the antivirus "is functioning correctly and all settings show it as active," that the notice can appear when Windows starts and again at random after that. It also keeps coming even if you switch notifications off. Every supported version of Windows is on the affected list, Windows 10 included. The fix arrives in a future Defender update. No date yet.

Here's how to check for yourself. Open the Start menu, type Windows Security, and open it. Click Virus & threat protection. If that page says no action is needed and Real-time protection is on, the pop-up is the bug and you can close it. Defender is the antivirus [we said was enough on August 13](https://www.freshfromcache.com/do-you-need-antivirus/), and this changes nothing about that.

The real notice comes from Windows Security itself, looks like every other Windows notification, and never gives you a phone number or asks you to install anything. A web page that says your antivirus is off and wants you to call someone is a scam.

Sources: [Microsoft](https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-25h2?ref=freshfromcache.com) and [BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/?ref=freshfromcache.com)

## The FTC says Amazon hid a surcharge behind its Sponsored search results

When you search on Amazon, some of the products mixed into the results are labeled Sponsored. Brands bid for those spots in an auction, and for years Amazon told them it ran a "second price" auction, where the winner pays one cent more than the next highest bid. On August 31 the FTC and 22 state attorneys general, Washington and Idaho among them, sued Amazon in federal court in Seattle. The complaint says that starting in 2019 Amazon added an undisclosed charge it called a "soft reserve price" internally, that by 2024 advertisers were paying their full bid about 80 percent of the time, and that the surcharge was turned up ahead of Prime Day and Black Friday. Amazon's own documents, as quoted in the complaint, describe "a surcharge hidden in it" and an "invented auction participant." The FTC puts the take at tens of billions of dollars from more than a million brands and sellers, over 500,000 of them small and mid-size businesses.

Amazon calls the suit "misguided" and says "in no scenario does an advertiser pay more than their bid." It also says the complaint cites no evidence of higher prices for shoppers, and that its average cost per click was flat, adjusted for inflation, from 2019 to 2024\. The FTC's chairman said the higher costs "were largely passed on to American consumers." Nobody has put out a number on that, and a complaint filed August 31 is a long way from a verdict.

Amazon's own advertiser page says Sponsored products can appear at the top of, alongside, or within shopping results, so scrolling past the first few doesn't get you to a clean list. Look for the Sponsored label on each result before you compare prices. This is the second Amazon money story in a row; [last week it was the crossed-out prices on Amazon's own devices](https://www.freshfromcache.com/also-this-week-2026-08-28/).

Sources: [Federal Trade Commission](https://www.ftc.gov/news-events/news/press-releases/2026/08/ftc-states-sue-amazon-over-secret-ad-surcharge-scheme?ref=freshfromcache.com), [Amazon](https://www.aboutamazon.com/company-news/amazon-ftc-sponsored-ads-lawsuit-response?ref=freshfromcache.com) and [Amazon Ads](https://advertising.amazon.com/en-us/solutions/products/sponsored-products?ref=freshfromcache.com)

## Nineteen browser add-ons turned on the people who installed them

A security firm called Socket published the details on August 27\. Nineteen extensions for Chrome and Edge, most of them small utilities like SEO checkers, crypto price tickers and a tool for re-enabling right-click on pages that block it, were carrying the same malware kit. Once installed, it stripped the security rules from every page you visited, slipped its own code in, and pulled down modules to do the actual work. The ones Socket watched drained cryptocurrency wallets, recorded whatever you typed into password fields on any site, and put up a fake "Chrome update available" page that tells you to paste a command into your computer.

Fourteen of the nineteen were built to be malicious, published clean, then updated with the malware once they had users. The other five were real extensions, written by real developers, that the criminals bought. The biggest, a right-click enabler sold under the name Enable Right Click & Copy, had about 70,000 Chrome users when the bad update went out. Chrome updates extensions on its own, and nobody is told when an extension changes hands. Socket says one with 10,000 users can be bought for under $2,000\. Google removed the Chrome listings. The Edge listing was still live when the report came out, with a fresh update from August 14, and was gone by September 3.

In Chrome, type chrome://extensions in the address bar. In Edge, edge://extensions. Remove anything you don't recognize or haven't used in months. If one of the extensions on Socket's list was installed, treat every password you typed in that browser as exposed and change them, starting with email and banking; [a password manager makes that an afternoon instead of a month](https://www.freshfromcache.com/start-using-a-password-manager/). [Our Chrome and Edge settings walkthrough](https://www.freshfromcache.com/chrome-edge-privacy-settings/) covers the rest of that page.

Sources: [Socket](https://socket.dev/blog/chrome-edge-extension-wallet-drainer?ref=freshfromcache.com) and [BleepingComputer](https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/?ref=freshfromcache.com)

## Android 17 hides site names from the network and lets your carrier close a 2G scam door

On August 27 Google described four network protections in Android 17, which is on Pixel phones now and reaching other brands through the rest of the year. The first is a scam fix. Crooks have been using portable fake cell towers called SMS blasters, priced from about $3,000, to force nearby phones off 5G and LTE onto old 2G, where the carrier's spam filters cannot see the text that follows. Android 12 added a manual switch to turn 2G off. Android 17 lets your carrier turn it off for you, by default, with no setting to find. Google hasn't said which carriers are participating.

The second is called Encrypted Client Hello. Even on a locked-padlock HTTPS connection, the site's name can still be readable to whoever runs the network, whether that's your internet provider or the coffee shop's Wi-Fi. Android 17 hides that name from the start of the connection, and Google calls it the first major phone system to do so broadly. The catch, in Google's own words, is that it works "for supported websites and apps," so the protection grows as sites adopt it, and it does nothing about [the sites you log into selling what they know](https://www.freshfromcache.com/what-is-a-data-broker/). Two smaller ones round it out. Apps now have to ask before they scan your home Wi-Fi for your TV and cameras, and website certificates have to appear in a public log, which makes a forged one easier to catch.

The only thing to do is take the Android 17 update when your phone offers it.

Sources: [Google](https://blog.google/security/new-android-network-security-protections/?ref=freshfromcache.com) and [9to5Google](https://9to5google.com/2026/08/27/android-17-network-security/?ref=freshfromcache.com)

That's the week.

If you are new here, [Start Here](https://www.freshfromcache.com/start-here/) collects the pieces worth reading first, and [the Tuesday email](https://www.freshfromcache.com/newsletter/) carries the whole week in one place.