Auto-generated from what's already tagged elsewhere in the graph — correlatable Radar items, P1 KEV entries, tactical-tier reports, open critical/high hunts, plus impersonation infra (a lookalike on live C2 or operator hosting) and fresh MENA malware IOCs. Nothing here is a new judgment call; it's the existing tagging discipline surfaced in one place instead of requiring a manual scan across pages. Also available as a machine-readable feed → for detection pipelines.