Assetnote scanners mistakenly attack NTP volunteer server linked via Tesla CNAME
A volunteer running an NTP pool server discovered persistent attack traffic, including Log4Shell-style payloads, arriving from AWS-hosted IPs tied to the security firm Assetnote. The traffic carried Host headers referencing pool-ntp.tesla.com, a domain Tesla points via CNAME to the public NTP Pool, causing Assetnote's scanners to treat the volunteer's server as a Tesla-owned asset. The issue was reported and resolved after Assetnote's team responded.