According to a recent Bloomberg report, the US National Security Agency was not only aware of the existence of the critical Heartbleed, but was also systematically exploiting it to collect data.
The US government, however, denies the allegations, stating that the NSA was unaware of the vulnerability until it was made public by security researchers.
According to the “Vulnerabilities Equities Process” principle, which governs the NSA's internal regulations, the secret service is inclined to disclose vulnerabilities that are identified, unless there are legal or national security reasons.
“When federal agencies discover new vulnerabilities in commercial and open-source software – so-called “zero-day” vulnerabilities because the developers of the vulnerable software had zero days to fix them – it is in the national interest to responsibly disclose the vulnerability rather than holding it for investigative purposes or data collection,” the director of the National Intelligence Service said Friday.
The government may occasionally allow the exploitation of a zero-day vulnerability for information gathering, strictly and only after approval from all relevant agencies.

