My understanding is this happened:
* Microsoft writes codes with bugs
* NSA writes exploits for said bugs and a worm based on them
* ShadowBrokers leak the NSA exploits and worm
* Random hackers take the NSA worm and combine it with a ransomware payload
So the NSA wrote the exploits and by not reporting the vulnerabilities they found they exposed the public to others finding the vulns or their findings and/or exploits leaking.
I don't believe that, however I do believe they sat on this vulnerability without disclosing it to Microsoft. This particular piece of software may not be theirs, but it may as well be.
People should keep systems under their responsibility up to date.
And people should disclose security vulnerabilities.
If you controlled a piece of hardware, you may not have had a choice to upgrade.
The lesson is that closed-source is anathema to a good security policy.
It's a bit horrendous because the NSA would have us believe that they're supposed to work proactively on the behalf of Americans. But then again, we all know that's not what the NSA actually does.