A warning went up on the Steam subreddit earlier today cautioning Steam users—so, pretty much all of us—to avoid opening profile pages of other users, and also their own activity feeds. The message is intentionally vague to help avoid spreading details about the exploit and how to use it, but it was posted by a subreddit moderator, while another mod says he's "investigated and created proofs of concept for this exploit."
A Valve rep said that a fix has now—as of about 12:05 pm ET—been published, so the problem should be taken care of. If you think you were caught by the exploit before the fix went live, the message says you should change your Steam password, enable the mobile authenticator (which you really should be using anyway) or, if you already use it, go into the settings and de-authorize any other computers on Steam Guard, and then restart your modem or change your IP. A full scan of your system with a malware/anti-virus scanner probably wouldn't hurt either.
Details of the exploit, which we can talk about now that it's been fixed, are available here.
Update: The post initially warned that a client update was required. It was in fact an issue with the Steam website.
Image credit: DiglidiDudeNG