1) The NSA's comprehensive subversion of information technology vendors into making it easy for the NSA to gain access to data. 2) The scale to which the NSA has been allowed to siphon that data from the most optimal places for an attacker.
One of the first things I point my developers at when they ask about crypto is http://www.daemonology.net/blog/2009-06-11-cryptographic-rig.... Nothing in there has changed. However, you probably want to assume that if you're using, say, the Microsoft CrypoAPI or Java JCE that you cannot be assured that a mechanism to access your data isn't present.