Cool. Thanks for digging, I found some of the same links while looking into this.
While I wait for the patch going into KVM, what is the different ways to prevent this? Is there anything I can do to disable SSM and/or something on host or VM? (bios/kernel/proxmox/vm-config) - except to stay on...