Just noticed this and thought it was worth mentioning for anyone that is working with these CMS systems. Check out the story on ZDnet.com Updating the security on your CMS systems is mandatory if you dont want to be a victim of this vulnerability.
I noticed that on the joomla.org site and updated all mine at the weekend. It's always worth checking back frequently
If you're using Joomla, it's better that you often check the latest update patch in Joomla community forum. In addition you can use notification feature in Joomla forum.
Yes it is good to keep checking on the Joomla site for updates. They have 1.0.10 available now that should address all those vulnerabilities. Hope to see the new version 1.5 soon. That is supposed to be very good.
As far as I know new features in Joomla 1.5 are : tableless, ajax backend, enhanced graphic user interface etc
Also v 1.5 is supposed to make fewer server requests making Joomla run faster and also eliminate the file ownership problems such as when you add new extensions, 1.0x versions give file ownership to Apache which can sometimes cause problems. All in all v 1.5 will be a major release update.