Not a big fan of Microsoft in general, and I generally distrust anything it does, but I'm beginning to like this Brad Smith fellow. He's been pushing for quite a few privacy initiatives inside Microsoft, and he's now also taking on NSA and calling for a Digital Geneva Convention.
I also think Microsoft "got lucky" this time. Shadow Brokers sit on EternalBlue for at least 6 months. They could've released it before the NSA even alerted Microsoft that such a bug exists in its operating system (probably earlier this year). That would've hurt Microsoft's image a lot more.
So I think this should also be a warning to Microsoft (and other software companies). If there is some other backdoor in Windows or bug on which Microsoft may decide to sit on to give the NSA a few extra months to exploit it, its image could be hurt a lot. Some other group may discover it and and then turn it into another global ransomware attack, before Microsoft even has a chance to patch it.
So lesson of the day: don't do back room (or door) deals with the NSA, whether because of fear, for money, "patriotism," or some other reason, because it could come back and hurt you 10 times more when you're put in the spotlight as the main party responsible for a global attack.