AI-Built Academic Apps and Student Data Exposure
Score: 7/10

AI-Built Academic Apps and Student Data Exposure

Rapidly deployed AI-built educational applications are collecting sensitive student data, including PII and biometric inputs, often without basic security configurations or privacy policies.

Executive Summary

A recent investigation by Censys highlights a significant increase in AI-built web applications targeting students and children. These tools, developed using platforms like Lovable and Replit, allow non-technical users to bypass traditional 'competence gates' for data ingestion. The research identified over 4.37 million AI-labeled sites, a subset of which specifically targets K-12 students for homework assistance, GPA calculation, and college admissions simulations.

While most of these sites are not intentionally malicious, they exhibit severe security negligence, such as missing privacy policies, default platform branding, and exposed administrative credentials. The data collected often includes highly sensitive content such as photos of homework, voice recordings, and live screen shares, which are stored in backend services like Supabase or Firebase that may not be properly secured.

Of particular concern is the discovery of an AI language platform, Lingua AI, hosted on an over-exposed server (185.106.177[.]145) alongside post-exploitation tools like NPS. This intersection of accidental data collection and aggressive network infrastructure represents a significant risk to the privacy and safety of minors in the educational sector.

Key Details

Threat Name

AI-Built Academic Data Exposure

Affects

—

Adversary

—

MITRE Techniques

Malware/Tools

NPS

Report Score

7out of 10
Quality Score
Good
IOC Quality7
TTP Details6
Detection Guidance9
Enterprise Relevance5
Clarity & Structure9
Technical Depth7

Sources