/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

NSA says it discloses 91% of vulnerabilities it finds, but sources say it often uses those vulnerabilities first

NSA says how often, not when, it discloses software flaws  —  The U.S. National Security Agency, seeking to rebut accusations that it hoards information about vulnerabilities …

Reuters Joseph Menn

Context & Ripple Effects

This 2015 Reuters report captured the NSA's public defense — that it discloses 91% of the flaws it finds — at the height of post-Snowden accusations that the agency stockpiles exploits rather than passing them to vendors. The number was carefully framed: how often it discloses, never when, leaving vendors and users unable to judge how long a retained flaw stays live.

The years after sharpened both sides of the argument. The Shadow Brokers leak appeared to show exactly the hoarding risk critics warned about NSA-held exploits surfacing in a public dump, while researchers found only 4,183 of roughly 76,000 flaws discovered over a decade had been exploited in the wild exploitation data suggests most disclosed flaws go unused. The administration responded by codifying the trade-off into inter-agency disclosure rules with annual reviews of every retained flaw the Vulnerabilities Equities Process rules.

First-order effects

  • Vendors and their customers get no timeline from the 91% figure — a flaw counted as 'disclosed' may have armed US operations for months or years before a patch exists, so defenders cannot calibrate exposure.
  • The NSA itself runs on both sides of the line: it publishes top-25 lists of flaws Chinese state-sponsored hackers are actively exploiting its own defensive advisories even as sources describe it retaining findings from offensive work.

Second-order effects

  • Allied signals agencies treat disclosure counts as competitive transparency — GCHQ publicized over 20 disclosures in a single year, including iOS flaws — pressuring the NSA to keep publishing aggregate stats to defend legitimacy.
  • Every retained flaw is latent attack surface: the Shadow Brokers pattern shows stockpiles can escape government control entirely, converting a classified equities decision into a global incident affecting every user of the affected software.

Third-order effects

  • Sources now describe the NSA red-teaming Anthropic's Mythos models to find vulnerabilities in Microsoft products and other widely used software — if AI-accelerated discovery becomes standard, the disclose-or-retain decision scales up and the annual-review cadence of the equities process comes under pressure to default toward faster disclosure.
  • With the National Vulnerability Database on pace to roughly double its yearly tally flaw volumes climbing sharply, the structural question shifts from 'how many' to 'how fast': retention economics weaken as discovery accelerates and leak risk compounds, pointing toward codified disclosure deadlines rather than discretionary percentages.

The trend: Government vulnerability handling is moving from opaque discretion toward quantified disclosure regimes, but accelerating exploit discovery — now augmented by commercial AI red-teaming — is forcing the retain-versus-report trade-off to be made faster and under more public scrutiny.