NSA says it discloses 91% of vulnerabilities it finds, but sources say it often uses those vulnerabilities first
NSA says how often, not when, it discloses software flaws — The U.S. National Security Agency, seeking to rebut accusations that it hoards information about vulnerabilities …
Context & Ripple Effects
This 2015 Reuters report captured the NSA's public defense — that it discloses 91% of the flaws it finds — at the height of post-Snowden accusations that the agency stockpiles exploits rather than passing them to vendors. The number was carefully framed: how often it discloses, never when, leaving vendors and users unable to judge how long a retained flaw stays live.
The years after sharpened both sides of the argument. The Shadow Brokers leak appeared to show exactly the hoarding risk critics warned about NSA-held exploits surfacing in a public dump, while researchers found only 4,183 of roughly 76,000 flaws discovered over a decade had been exploited in the wild exploitation data suggests most disclosed flaws go unused. The administration responded by codifying the trade-off into inter-agency disclosure rules with annual reviews of every retained flaw the Vulnerabilities Equities Process rules.
First-order effects
- Vendors and their customers get no timeline from the 91% figure — a flaw counted as 'disclosed' may have armed US operations for months or years before a patch exists, so defenders cannot calibrate exposure.
- The NSA itself runs on both sides of the line: it publishes top-25 lists of flaws Chinese state-sponsored hackers are actively exploiting its own defensive advisories even as sources describe it retaining findings from offensive work.
Second-order effects
- Allied signals agencies treat disclosure counts as competitive transparency — GCHQ publicized over 20 disclosures in a single year, including iOS flaws — pressuring the NSA to keep publishing aggregate stats to defend legitimacy.
- Every retained flaw is latent attack surface: the Shadow Brokers pattern shows stockpiles can escape government control entirely, converting a classified equities decision into a global incident affecting every user of the affected software.
Third-order effects
- Sources now describe the NSA red-teaming Anthropic's Mythos models to find vulnerabilities in Microsoft products and other widely used software — if AI-accelerated discovery becomes standard, the disclose-or-retain decision scales up and the annual-review cadence of the equities process comes under pressure to default toward faster disclosure.
- With the National Vulnerability Database on pace to roughly double its yearly tally flaw volumes climbing sharply, the structural question shifts from 'how many' to 'how fast': retention economics weaken as discovery accelerates and leak risk compounds, pointing toward codified disclosure deadlines rather than discretionary percentages.
The trend: Government vulnerability handling is moving from opaque discretion toward quantified disclosure regimes, but accelerating exploit discovery — now augmented by commercial AI red-teaming — is forcing the retain-versus-report trade-off to be made faster and under more public scrutiny.