I see a lot of people bagging on Java but I think the real problem are the browsers. Java is the one being used in this attack but next time it could be Flash or Acrobat or any other plugin or even 3rd party Javascript scripts. The default behavior of browsers should be similar to flash-block, Ghosterly and other similar plugins: the plugin only runs when the user requests it by acknowledging the source and hitting a "play" button inside the page. No auto-loaded code should ever run.