>To put it another way, the alternative is not that the NSA would have Microsoft about EternalBlue years ago, but that the underlying bug would have remained un-patched for even longer than it was (perhaps to be discovered by other entities like China or Russia; the NSA is not the only organization searching for bugs). False dichotomy. The choices are not only: a) NSA pays lots of money to identify exploits and then…
China and Russia are reporting vulnerabilities? Got a source for that?