Link? What link? Are we talking about the link to the CtNet article?
Anyway, I think this story is extremely misleading, so much so I wonder if it is intentional. Widgets do not download, install themselves and run without the intervention of the user.
It's that simple. Nobody is all of a sudden going to find that a widget has been surreptitiously slipped into their system by a malicious website and invoked all without the awareness of the user. I'd call it a crock. In fact I think I will.
A few years back Microsoft paid 'researchers' for white papers claiming open-source was a bad idea. Wonder if the so-called expert referenced in the article is being paid by Microsoft.