Naked Security's +Graham Cluley is very proud of the animated GIF he just made..
Unless someone missed a security hole in the operating system, malware on any system still requires an action from the user.  It doesn't "just happen" to get installed.  You have to run as root, or authorize the malware to be installed.  Even the Java exploit required visiting a bad Website or having the system exposed by something internal to the network.  Apple has always been about making computers easier to use for people who don't understand logic and engineering, but I really think we need to consider forcing people to learn something more than "It doesn't get viruses" and "Patch often and use anti-virus software."  If you don't understand how the threats function, you have a much higher risk of being affected by a passive or active attack.
