When I read the post on Engadget, I had to read it twice.
There is an unpatched bug in Gmail that exposes your e-mail account and the accounts of all of your contacts to anyone who has the knowhow to view it.
When you login to Gmail, your details are contained in a JavaScript file in your browser. If you visit a site that can grab those details, poof, your Gmail account is opened, cataloged and ready to receive some spam.
Google will probably fix this before they release the final version of Gmail (as Thomas at Engadget points out – Gmail is still in Beta ;)).