>> Privacy advocates also worry that to carry out its hacks, the FBI is using “zero-day” exploits that take advantage of software flaws that have not been disclosed to the software maker.
I imagine that's not the only attack vector. I would be surprised if FBI / CIA / NSA don't seek (direct or indirect) commit access to popular open source projects.