This weeks patch Tuesday made things really interesting with the announcement by the NSA that Windows Server 2016/2019 and Windows 10 had a critical vulnerability in their CryptoAPI component (Crypt32.dll). Essentially, the vulnerability pertained to how Elliptic Curve Cryptography (ECC) certificates were validated.
There are lots of great write-ups here, here, and a test here. Why did the NSA choose to work with Microsoft on responsible disclose prior to the patch the rather than weaponizing it themselves? Maybe, just maybe, Nation State actors were already exploiting it...