NIST has weighed in on how to use TLS: http://tools.ietf.org/html/rfc6460
I am not aware of any proposed attacks on the approved cipher suites that are anywhere near feasible. TLS deployment is far behind known best practice. We should do something about that.