They are already weaponized, and have been for a while. The time to start taking information security seriously was 15 years ago.
Yet we openly embrace hardware we don't understand riddled with flaws and software we can't see in to or audit and makes requests without our consent. When you login to $bankingApp are you aware of all the DNS requests, information it's POSTing?
Heck, Facebook's SDK derps and cripples many applications. Our software stack is built on a mountain of hacks, flaws and quite frankly, insanity.
Computing, from the hardware to the kernel needs completely revamping, because nothing else will be able to salvage our current environment.
Its presence manifests a different set of skills. Exploitation is not necessary. Presence itself is enough of a warning.
It says “we’re equal now. We can be in your turf, sleep for a long time and even use your own companies as launch pads”.
Lots of these so-called "Cyber weapons" are operated by actors who are very effective at leaving no trace.
It's been in the background before but in the reports about this SolarWinds issue the "leaves no trace" angle is starting to be emphasised much more.
Not knowing if or what has been compromised means that the attacker can choose when or how to use the information they obtained and the victim will be surprised, even a long time down the line.
This hack by itself should be proof that the NSA has no such capabilities. And, no, stopping this hack would not have compromised anything. They could have tipped off any one of a rather large number of security researchers, companies, or vendors affected who would have gladly made up a believable story as to how they noticed this.