While working on the border ACL filtering, I noticed that prefix 224.0.0.0/4 (multicast) has been removed from the "special-ranges4" list in the last few years, and I'm not sure why. This means that multicast (source) traffic is no longer being filtered at our border.
Also several ranges (/24s) seem to have been added to the special-ranges4 list that don't appear to be special ranges, and may just have been added to effectively block those networks. A separate prefix list should be used for that.