HeadlinesBriefing favicon HeadlinesBriefing.com

Cyberattack from Tesla IP addresses traced to Assetnote scanner error

Hacker News •
×

UPDATE: RESOLVED - Patrik from Assetnote reached out with a gracious message and the issue has been resolved. The author noticed unusual attack traffic from three AWS IPs (54.165.75.96, 35.168.63.24, 52.44.200.251) carrying Assetnote user agents and targeting their server with various exploits including Log4Shell and SSRF attempts. The traffic used pool-ntp.tesla.com in Host headers, which CNAMEs to pool.ntp.org - a round-robin of volunteer NTP servers including the author's IP.

Assetnote appears to have mistakenly included the author's server as a Tesla asset in their scanning scope, causing approximately 8,000 exploit attempts over two days. The author emailed Tesla to warn them about unintentionally scanning strangers' IPs through their NTP pool configuration.