In the meantime, experts keep advising users to disable Java if they dont need it for their everyday tasks.
Well, I do need it, so I find that "expert advice" somewhat specious, even annoying. Java's the current whipping boy, but a whole lot of programs have vulnerabilities. That's why we layer security - and install patches. Including patches to Facebook, Apple, and Microsoft.