Giant SQL Injection Spider Attack
There is a giant Spider bot net based SQL Injection attack going on right now. This has personally affected some friends of mine, and I have been reading about it on the CF-Talk list.
Unfortunately, there does not seem much that can be done about it other than to try to ride the storm out. I have not seen anything in the Tech press about this yet, but they seem to be a day late and dollar short anyways.

I think you're right - this will go away eventually :)
The good news is that many have written providing ideas to block the attacks (from code changes to configuration changes), as well as ways to revert whatever changes are made by this current wave of attacks. The easiest way to find them is to go to coldfusionbloggers.org and search for hack, and there are (today) 2 pages of entries going back to 7/18 mostly on the topic. Hope that helps. I may have more to say on my own blog soon.
I saw one post on CF-Talk where they had gotten 40000 attacks in the last 24 hours.
I was able to find the problematic template by searching the IIS logs for the word "DECLARE" which pulled up the template and variable reseponsible.