Oracle’s Java platform is becoming an increasingly infection vector for malware.

This graph says it all:

Java and PDF Exploit Attempts

Microsoft asks, "Have you checked the Java?" (click for full article)

The full article is a bit thick but has some interesting points.  I’ll give you the punch line:  The vulnerabilities that account for the huge spike in Q2 2010 had already been fixed in the most recent version of Java.  In other words, users who stayed up-to-date were safe.

The moral of the story:  Keep your programs updated.  The Java update notification looks like this:Java Update Notification

Alternative Moral:  If you don’t need Java, uninstall it.