In other words, it keeps bad guys out of the middle, not the end point. That's all SSL can do, even if it works perfectly. Bad guys will still own end points, in both the conventional sense of the word own and the pwning sense of the word own. SSL can not (directly) do much about that. If you speak SSL to a bad actor, well, there aren't any other actors between you and the bad actor, but you're still speaking on an encrypted, authenticated channel to a bad actor.
This is in contrast to the DNS infrastructure in which it is sensible for a TLD owner to attempt to prevent "people they don't want on their TLD" (more generally than "bad guys" since a lot of the restrictions enforced are far beyond that).
I remember reports in the past decrying CAs for issuing certificates for phishing sites in the style of "gooogle.com" etc.
You are right that some news articles and reports continue to chastise CAs who issue to sites in the style of "gooogle.com". Do not let them trick you - that is only their opinion on the matter. It is NOT against the industry rules to issue those certificates.[1]
What IS against the rules is to issue a certificate for "domain.com" to someone who has not proven ownership of "domain.com". That is the BIG no-no that leads to consequences such as being un-trusted. There are standardized methods for meeting the burden of proof, and every CA uses more or less the same mechanisms to do so.
Let's Encrypt, or any CA, may issue a certificate to "paaypal.com". Even if that site was a Paypal phishing site, a CA is under no obligation to revoke the certificate or prevent that user from getting another certificate.
Some CAs CHOOSE to do this. To some extent, I think it is sensible to try to thwart malicious use. However, the case is often made that CAs and SSL certificates are not meant to "police content", and furthermore, that they are not very effective at doing so.
Flagging a malicious site through a tool like Google's SafeBrowsing is significantly more effective than revoking their SSL certificate.
[1] Except for a more recent stipulation that Microsoft added to their root program. If they request the revocation of a certificate they believe is malicious, the CA is expected to comply. If they dont, they are only at risk of being punished by Microsoft.
Though I also liked .io, and felt the higher pricing and harder registration kept a lot of the squatters away.
The certificate is a kind of "encryption only" certificate, it's treated as a second class citizen (you might get a grey lock for example) so it's encrypting the communication but it's not very useful for convincing you that you're talking to your bank when you aren't.
Of course if LE don't do a good job of (1) then we're f*ed because they'll issue certificates to bad actors and LE have a hard job because now they're trusted they're a good target for DNS cache poisoning etc.