NSA reportedly knew about it at least 2 years ago.
http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html
We spend umpity-umpteen billion dollars on the NSA every year, but yet the government has to rely on Google to find this stuff and tell them about it?