Earlier quoted context omitted.
The NSA hoards vulnerabilities for the same reason the military has guns. Vulnerabilities are fundamentally unlike guns. Because vulnerabilities can be independently discovered or accidentally released, then reproduced in vast quantities and used against the public and civilian infrastructure of both us and our allies - largely with impunity. If wannacry was a gun, it'd be a gun that fired backwards and sideways at t…
Correct me if I'm wrong but WannaCry used vulnerabilities that already had patches. How does reporting these vulnerabilities earlier instead of keeping them fix this situation? You'd still have the problem of slow updates regardless.
Normally full disclosure happens after about 45 days (I'm not an expert, I don't know exactly) but in special cases the time is extended.
This would probably be considered as a special case as Microsoft exceptionally released updates to unsupported, old versions of Windows and the hole itself was critical.
Please note that WannaCry hit in mid May - not that long time ago.
Shadow Brokers Group public disclosure of stolen tools from NSA happened in April.