I'm seeing a ton of these IDS rule hits as well. Rule ID 1-16295 "Kaspersky antivirus library heap buffer overflow - without optional fields".
Over 6,100 starting around 4:45pm EST on Tues 6/13 (nothing noteworthy before then).
I'm guessing that all of the remote sources are CDN's. HWCDN, LLNW, Akamai, Edgecast, and Level 3. 4 of the top 10 have contributed to between 600 and 1000 events each, and others of the top 10 are 80 or fewer events each.
We are running firmware MX 18.107, and that has not changed recently. I'm not aware of any other changes in our environment which could be contributing to this.
I'm taking a wild guess that maybe something changed with NBAR definitions, and it's causing false-positives? That said, I have no idea what legitimate traffic would be hammering from CDN's what looks like roughly every 4 to 5 minutes per each affected local computer at literally all hours of the day.