This sounds like something that HPKP ( https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning ) could have prevented and CAA records ( https://letsencrypt.org/docs/caa/ ) could not. But HPKP is deprecated.
The problem is that there is no out-of-band mechanism for update like other devices.
If your CA certs are bad on your mobile application, you can push an out-of-band update via the device's app store.
If your CA certs are bad on a website you access via your browser, the means of updating them is... the browser. You can't get new certs without using a TLS connection you didn't want to trust anyway.
CAA records (with ACME account bindings) can prevent this.
HPKP was deprecated because it was too dangerous to be deployed in production.
Google Chrome has a static, preloaded pin set for Google's own web properties, I guess these minor ccTLDs were not covered by that.
Only if someone had visited that site before, and it’s insanely risky and would damage far more sites than would save.
The issuing was detected almost immediacy thanks to CT, and as we move to shorter certificate lifetimes the impact is continually reducing.
The CAA record in dns is a weak link though.