Of course, "just revoke" doesn't actually work: serving a outdated certificate revocation list, or preventing a connection to the OCSP ("is this cert revoked?") server causes browsers to trust "revoked" certificates. Worse, lots of software doesn't even bother to do this check. This is why the browsers hardcoded a list of compromised certificates last time.
This is even worse, though, because a lot of "real" certificates depend on this CA. Also, there are no logs to make a blacklist of "bad" certificates, so you can't just revoke a handful...