So, for those who use Windows Defender we still need to add that key? I've it disabled and so far, nothing on Windows Update, still on build 16299.125
Yes. Defender sets the key with latest Definition Updates. You can also set it manually, afterwards the Update will appear in WU.
You could apply the uCodes patches using this link Security flaw patch for Intel CPUs could result in a huge performance hit On linux Security flaw patch for Intel CPUs could result in a huge performance hit