NSA was not aware of the recently identified vulnerability in OpenSSL, the so-called Heartbleed vulnerability, until it was made public in a private sector cybersecurity report
Or perhaps the "private sector cybersecurity report" was a IRC chat two years ago for l33t haxors.