The media is trying for ratings. To get them, they over hype things. I am also convinced that journalist become journalist because they cannot do math or understand science, which to some degree means technology. So, they have little understanding of HeartBleed, what it does, how it does it, or what it means.

To put things in some perspective check out: Answering the Critical Question: Can You Get Private SSL Keys Using Heartbleed?
The quick explanation of HeartBleed is that it is an exploit run on SERVERS that use the OpenSSL code and only certain versions of it. Anti-virus and anti-malware software cannot fix or protect you from such a problem.
So, if someone is selling protection, they are selling into the hype-generated fear. They are opportunists, which is not necessarily a bad thing. But, if they are providing software for your computer they are only providing some people peace of mind. You can get peace of mind for free from understanding the reality.
Cloudflare’s explanation is what I’ll call medium level technical. It is readable and I think SL users will probably understand it. But, the TL;DR is:
The exploit in the server code will allow a hacker to trick the server into sending them the code they need to decrypt HTTPS encrypted network packets. When you browser talks to a bank or other server using OpenSSL the network packets traveling back and forth are encrypted. To date no one has been able to break that encryption. So, your conversation is secure.

