It’s a pretty rare event when DHS warns to disable the Java in your browser, but they have because of a Zero Day security flaw which allows infected applets to infect your computer via your browser and allow elevation of privileges to occur.
  Once this occurs, your computer will no longer keep your sensitive data private.
  The apps and code to do this are out in the wild, so this is not theoretical.
  So… do the recommended.
  How to do it:
  https://www.java.com/en/download/help/disable_browser.xml
  Source:
  http://www.zdnet.com/homeland-security-warns-to-disable-java-amid-zero-day-flaw-7000009713/