A server operator discovered persistent attack traffic originating from Tesla's network infrastructure, traced to Assetnote security scanners mistakenly targeting their machine. The traffic resulted from Tesla's pool-ntp.tesla.com subdomain CNAMEing to the NTP Pool, causing Assetnote's asset discovery to misclassify unrelated NTP servers as Tesla assets and send exploit payloads including Log4Shell and SSRF attempts.