http://cypherpunk-handbook.i2p/articles/openbsd.html
QEMU/KVM, Xen, Hyper-V, VMware, VirtualBox, and other hypervisors
were not built from scratch with security as the first priority. VM
management can also be weakened by the surrounding operating system,
including components such as systemd. Hardware passthrough greatly increases the attack surface.