Alerts interpretation - Black list hit vs update vs attack

How do I interpret this?

Every time the reason is update I guess the list is being updated but in the decision column appears number of ban IPs, is that the number of IPs banned? what about deleted IPs? because the numbers doesn’t match
How this table looks like when the reason is not an attack but a hit from an IP blacklisted by the community list?

+----+-----------------------------------+-------------------------------------------+---------+--------------------------------+-----------+--------------------------------+
| ID |               VALUE               |                  REASON                   | COUNTRY |               AS               | DECISIONS |           CREATED AT           |
+----+-----------------------------------+-------------------------------------------+---------+--------------------------------+-----------+--------------------------------+
| 67 | crowdsecurity/community-blocklist | update : +11586/-0 IPs                    |         |                                | ban:11586 | 2022-03-18 17:28:07 +0000 UTC  |
| 66 | crowdsecurity/community-blocklist | update : +11596/-0 IPs                    |         |                                | ban:111   | 2022-03-18 15:28:07 +0000 UTC  |
| 65 | crowdsecurity/community-blocklist | update : +11595/-0 IPs                    |         |                                | ban:72    | 2022-03-18 13:28:07 +0000 UTC  |
| 64 | crowdsecurity/community-blocklist | update : +11605/-0 IPs                    |         |                                | ban:82    | 2022-03-18 11:28:06 +0000 UTC  |
| 63 | crowdsecurity/community-blocklist | update : +11622/-0 IPs                    |         |                                | ban:67    | 2022-03-18 09:28:07 +0000 UTC  |
| 62 | crowdsecurity/community-blocklist | update : +11641/-0 IPs                    |         |                                | ban:77    | 2022-03-18 07:28:07 +0000 UTC  |
| 61 | crowdsecurity/community-blocklist | update : +11668/-0 IPs                    |         |                                | ban:71    | 2022-03-18 05:28:06 +0000 UTC  |
| 60 | crowdsecurity/community-blocklist | update : +11691/-0 IPs                    |         |                                | ban:96    | 2022-03-18 03:28:07 +0000 UTC  |
| 59 | Ip:51.142.99.17                   | crowdsecurity/http-probing                | GB      | 8075 Microsoft Corporation     | ban:1     | 2022-03-18 02:28:21.570902105  |
|    |                                   |                                           |         |                                |           | +0000 UTC                      |
| 58 | crowdsecurity/community-blocklist | update : +11735/-0 IPs                    |         |                                | ban:82    | 2022-03-18 01:28:07 +0000 UTC  |
| 57 | Ip:20.213.62.181                  | crowdsecurity/http-probing                | US      |                             0  | ban:1     | 2022-03-18 01:12:23.178110281  |
|    |                                   |                                           |         |                                |           | +0000 UTC                      |

And a quick question, by default are the bans applied to all bouncers?