I sincerely hope that nobody out there decided to visit the Miami Dolphins for at least the past week. The site
got hacked. The script would apparently only affect Internet Explorer browsers, on systems that hadn't installed a patch that has been available since October. As many companies out there trust Microsoft's patches as far as they can throw an ENIAC, they may not have finished testing the patch and thus not have gotten it installed already. (If it's a mission-critical system, I'd be testing the bejeezes out of any patch, regardless of the OS: Linux, BSD, Windows, OS400, you name it. Patches have been known to break things that weren't broken before.)
For those keeping count, Groklaw's webmaster Mathfox reports that the compromised websites were running IIS 5.0 on Windows 2000.