Heh. Yup. And I'd be especially concerned about code written for QEMU, as it's an unusual type of application. There's lots of example code and other writings about security in web applications which a language model is likely to have encountered in its training; hypervisors are much less frequently discussed.
https://www.backslash.security/press-releases/backslash-secu...