Alibaba's Fastjson 1.x library carries a critical deserialization flaw that attackers are exploiting in Spring Boot applications.
The Java-based trojan uses a modular architecture with encrypted plugins that can be dynamically loaded and updated from its command-and-control…