Android phones run Linux and get hacked to get root access. Routers, IoT devices, and lots of other hardware run Linux variants and get hacked all the time.
This idea that people hold that if only we didn't run Windows we'd all be more secure is silly and naive.
Once a vulnerability is used it is likely to be patched. A group that cannot be coerced to do something for you will close vulnerabilities as it learns of them because they are liabilities.
Also, moving away from microsoft will likely lead to the end of software monoculture. You need to research those vulnerabilities for each target. Oh, and it it would be much more than a fewer hours of research.
The software monoculture exists because of USERS. The vast majority of users don't want to have to learn three different OS, look+feel, GUI rules, etc. They just want the goddamn excel file that the CPA sent over that they need for their accounts receivable report to OPEN. Trying to convince governments to go to FOSS doesn't well work because the users slip back to things so that they can do their job the way they know how.
See, e.g. the city government of Munich, which after a decade of trying never got above about 60% of their users to switch to Linux, and is considering abandoning the effort.
Using new software today isn't like it was in the 90s, the OS is much less important. UIs can be delivered by web and all the user friendly UIs (all mobile OSes, and no desktop OSes) area ll similar enough that many users can't tell the difference. If this is the barrier to someone's national security...
There's been multiple attempts. Linus has even been directly asked to put backdoors in Linux.
There is even a contest to make code look normal, but do something malicious https://en.wikipedia.org/wiki/Underhanded_C_Contest
I'm sure the NSA is very good at that.
To put this into perspective, there's CPU modifications that can make a Linux or FreeBSD system mostly safe and secure against known classes of attack instantly just at the compiler and CPU level with a certain performance hit. Anyone wanting improved security could then use Linux with those CPU's probably buying some extra chips, too, to cover performance loss. You don't have that option with Windows.
http://www.cl.cam.ac.uk/research/security/ctsrd/cheri.html