The title is pretty much linkbait. If you change registrar-level things about your domain, they're now required to confirm your contact info with you. This isn't a "DDoS", or "deadly", or any of that nonsense: it's a new strategy to ensure whois data stays updated. Whether or not it's an effective strategy for keeping whois data accurate is another debate (I don't think it is), but talking about it like some maliciou…
That's bad.
The registrar is public information. The registrant's contact information is public (or at least publicly accessible). So, wait a year for people to get accustomed to clicking on links in emails from their registrar, pick a target domain, forge an email from the registrar, send it to owner contact with a link to a phishing page. Congratulations, enjoy your new domain.