Yes, securing the endpoint is hard, especially given the non-hardened OS and applications we mostly use. However, you can't extrapolate from that to say with certainty what has and hasn't been exposed via security flaws.
The USSR was much more successful at espionage than the US was, and they took a low-tech approach to it. For decades, they developed contacts within the govt, gave them money, and had documents handed to them by authorized insiders.
Let's not assume computer exploitation is the only culprit. History has shown a variety of techniques, even very low-tech ones, have been employed for espionage and it's impossible as an outsider to determine how much has been taken, by whom, and by what means.