This will give malware purveyors a whole new plethora of vectors to exploit insofar as social engineering goes.
Imagine regular user 'A' is surfing, looking for a cool new pair of shoes. They know that kewlShoes is their fav shoe company evar. Some entity has paid the huge fee to acquire the .shoes TLD in order to sub-let domains at whatever nominal fee they decide.
User 'A' browses to kewl.shoes instead of kewlshoes.kshoes and unwittingly becomes the latest drive-by-download victim happily handing over their credentials to who-knows-who.
I know this is broad and speculative, but think it is worth consideration.
Has there been other discussion about this out there that I haven't seen?