> How was this attack carried out? The malvertisers used a technique called “domain shadowing”. Attackers who have gained the ability to create subdomains under a legitimate domain do so, but the created subdomain leads to a server under the control of the attackers. In this particular case, the attackers created ad.{legitimate domain}.com under the legitimate site.
That's quite different. The attackers appear to have had full control of DNS in that case. Being able to control DNS is essentially the definition of domain ownership. Fraudulent issuance would be the smallest problem for a site affected by this. They'd have gotten a certificate from practically any CA issuing DV certificates.
Domain validation is messy and far from perfect, but this vulnerability is just inexcusable.