Honestly the only thing that really needs to be said: https://nso.group/@qwertyoruiop/110086216898968720
Are there any real CTF's done against OpenBSD to present this evidence?
When Luca Todesco (the person who wrote that toot) tells you your exploit mitigations are trash, you listen.
Like I said, I'm not going to make any claims to being an elite hacker. I have a cool job that I love, and I enjoy doing this stuff for fun too to keep my skills sharp. But reading through that presentation, there's nothing that made me pause and think "This is a game over scenario." If you have a moderately powerful bug with halfway decent primitives these mitigations aren't really going to stop anyone.
An elite team like NSO group? This isn't going to effect them one bit.