What about Stuxnet? Did they go to companies and told them to patch against that once it was out? We don't even know how many more times these things have happened in the underground and used by criminals. We have just one example of NSA doing this, and even that wasn't sufficient because the "horse was already out of the barn."