Executive Summary
A recent investigation by Censys highlights a significant increase in AI-built web applications targeting students and children. These tools, developed using platforms like Lovable and Replit, allow non-technical users to bypass traditional 'competence gates' for data ingestion. The research identified over 4.37 million AI-labeled sites, a subset of which specifically targets K-12 students for homework assistance, GPA calculation, and college admissions simulations.
While most of these sites are not intentionally malicious, they exhibit severe security negligence, such as missing privacy policies, default platform branding, and exposed administrative credentials. The data collected often includes highly sensitive content such as photos of homework, voice recordings, and live screen shares, which are stored in backend services like Supabase or Firebase that may not be properly secured.
Of particular concern is the discovery of an AI language platform, Lingua AI, hosted on an over-exposed server (185.106.177[.]145) alongside post-exploitation tools like NPS. This intersection of accidental data collection and aggressive network infrastructure represents a significant risk to the privacy and safety of minors in the educational sector.
