
Auditing a Self-Hosted Computer-Use Agent Stack for Element-Blindness and Checkout Abuse
pr0h0•
computer-use-agentsself-hosted-aigui-groundingopen-weight-modelsbrowser-automation




ShinyHunters is exploiting Oracle PeopleSoft CVE-2026-35273 by slipping past WAF protections and dropping web shells, a reminder that edge filtering alone cannot contain post-exploitation tradecraft when patching lags.

An audit-oriented guide to self-hosted computer-use agent stacks — covering Holo4, JEV-27B, GUI-grounding fixes for element-blindness, and Shopify's browser-agent checkout support — and how to stress-test each layer for abuse before putting it near real money or real accounts.