Indeed; this is a very important topic, and one I’ll be addressing in more detail soon, in relation to xPDO and how the new centralized core logic can help alleviate some of the potential for these new world vulnerabilities.
I also found some good principles to follow on AJAX Security here:
http://www.owasp.org/index.php/OWASP_AJAX_Security_Guidelines
And a couple of good links in the meantime to help you become more familiar with the prototype overloading or hijacking technique I believe this article is referring to. I would question the motivation of the Fortify-related article in much the same was as this following information was scrutinized on Slashdot, but it’s definitely worth keeping an eye on none-the-less.
http://events.ccc.de/congress/2006/Fahrplan/events/1602.en.html
http://it.slashdot.org/it/07/01/06/216245.shtml
There are also some very insightful responses in the Slashdot article... (and some typically stupid ones too, always fun to read!)