Could DNS responses have been hijacked as well?
Edit: Could this have been used to hijack/create TLS certificates?
Edit: Could this have been used to hijack/create TLS certificates?
Protection could be validating DNSSEC (most likely not)
Or using DoH (DNS over HTTPS) or DoT (DNS over TLS)