Is there any recourse for those who had coins stolen? Or should we assume we will never see them again? Sucks... I lost 0.09 BTC and my payout was set to 0.1

As with most things like this, plan for the worst and hope for the best.
The fact that the owners of the pool are still posting here is a good thing, but small operations need time to work this out, the timeframe is bad, I have sympathy for the guys.
As for recourse, no, you are on the cutting edge of technology, this, as somebody so aptly put it, is the wild west. Until there is some sort of regulation around it there will be nasty shits determined to try to steal what isnt there.
Unique usernames and passwords are the order of the day to at least offer some protection from the exposure of your details. When you have a vulnerability like this "seems" to be, even that would protect you from losing what is on that site. The middlecoin model seems to work quite well to battle this, but again, this is the net, nothing is 100% safe.
Gamble ONLY what you can afford to lose. Find a happy medium between cashing out and the typical charges for doing so.
I hope you get your BTC back..