I have friends who do security at Google, and they explicitly told me "we don't think the company was vulnerable and you don't need to change your GMail password." So as near as I can tell, the third-party sites and Google, inc, disagree about whether Google is vulnerable here.
You know the drill - If it's worth saying, but not worth its own post (even in Discussion), then it goes here.