However, NSA is strongly suspected of (known to?) having backdoored the Dual_EC_DRBG pseudorandom generator by inserting into the standard numeric parameters which allow cracking by those who generated them (i.e. the NSA).
https://en.wikipedia.org/wiki/Dual_EC_DRBG
This algorithm ended up in certain Juniper firewalls and a year ago turned out to have been covertly re-backdoored by unknown actors who replaced NSA's parameters with their own.
https://rpw.sh/blog/2015/12/21/the-backdoored-backdoor/
There was also another low-tech backdoor in these routers, again not clear who did it.
Snowden documents show that they have a budget allocated to the backdooring of cryptographic standards and products:
http://www.nytimes.com/interactive/2013/09/05/us/documents-r...