former33t,
I think sadly you may be wrong. A person is smart, people are stupid.
Users really dont seem to understand the risks, and this is why these forms of attacks, no matter how obvious they appear work time and time again. If it didnt people just wouldnt bother.
We need to take control and keep on with user awareness and education. I dont think it will ever eliminate the risk, but it should help to reduce. We can also use technology to remove the risks, and policies to help inform and enforce.
Keeps us in a job anyway

Don,
This just shows that there's a sucker born every minute. Users know not to execute remote files, but then forget about it when a celebrity dies? I think I'd be prone to fire any users that fell for this. For one they're using company resources to research the Jackson death. I'm guessing this is against policy. How much leeway should you give a user who violates company IT policy and compromises the network at the same time?