Any way, this just confirms the long disregarded notion that it is not possible to execute untrusted code without extreme level of considerations for hardware isolation.
In other words: any kind of "cloud" thing, or any hosted computations are at inherent risk of abuse from ISA level attacks.