Java has always been a software with many exploits and attacking potential. That is well known.
But what's the real point here? The real point here is that this only happens on websites who want to exploit users. But we don't want to do that and never will. So you can use java safely on igpmanager.
This situation is not new and everyone can protect himself by just not visiting sites he doesn't trust.
The problem is while you're using iGP you can't really surf the net because you have Java running. Some might say it's not a big deal, but I know sometimes on those long stints, or tracks like Monaco or Hungeray I'd like to browse around. But I don't trust it.