Everyone should fire up Software Update and pull down the new Java update, which does, in fact, patch the vulnerability in question (and it's a nasty one.)
Very much agreed. The vulnerability is in use in the wild, and all it takes is visiting a page with a certain java applet. No prompts will appear and the machine can be compromised.
Lion users may not see the security update, since Java is no longer installed by default, and is removed even if you do an upgrade from Snow Leopard. To check if it is installed, run the Java Preferences in the Utilities folder. If Java is not installed, you will see a prompt to download it. Just click cancel if you have no use for it.
Java and Flash are pretty much the two biggest security risks when browsing the web these days. I've got Flash uninstalled on all my machines now (using Chrome and it's sandbox only when I need Flash, otherwise I use a flash free browser). The Java plugin is only turned on if I want to play a demo at Gaikai.