Geohot has published his Hypervisor-Exploit!
It basically works by quickly allocating and deallocating memory, while glitching the memory bus. This way the Hypervisor thinks some repeatedly allocated memory is deallocated, allowing r/w-access and with some tricks r/w-access to the main htab.