First, not everyone has installed Java. It is pretty common, but you may not find it on your PC. There is enough risk for the government to put out these announcements (uncommon)...
You can download the latest version of Java (required for the needed security settings) from:
http://www.java.com/en/download/index.jsp
It is version 7u11. (Updated to reflect new version 1/14/2013) This new version resolves the exposure alerted by homeland security this week, but it's still recommended to disable java content in the browser as described below.
After installing this (on a Windows machine) you go to the system "Control Panel" from the Start Menu.
Set the control panel to view with "Small icons" if you don't see a "Java" icon with a little coffee cup. You should then see this app.
You can also just search for the "Java" app from the Windows Start Menu.
I attached the panel with the area you need to un-check highlighted in yellow:
You want to turn off "Enable Java content in the browser".
There is also another tool that you can install as an add-on to browsers like FireFox. It's called "NoScript". I use this to lock down any calls like this...
Marc