Apparently there has been a serious Java vulnerability discovered, which allows attackers to execute simple web-based attacks against people running current versions of Windows.
Disabling the Java plugin does not seem enough to prevent the problem, as the vulnerable toolkit is installed independently.
If Sun does not comply with the 'demand' to release an early patch for this, the exploit will be thrown out into the open.
More:
http://blogs.zdnet.com/security/?p=6082&tag=content;col1