I agree with most of your points; I'd just like to say that I'd never trust a "free VPN"... (Outside of "it's free since I host it".) I'd put most of my effort into vetting which VPN is best audited/trustworthy.
As an aside, the other big threat that sidesteps HTTPS certificate validation would be for the attacker to only serve HTTP. The browser will call this out in the URL bar at least. This can be mitigated by sites sending HSTS headers (forcing you to use HTTPS for future connections), but this isn't necessary universal. And requires having visited the site earlier on a "safe" network.