I don’t quite follow why a missing underscore results in a security problem. It seems like it must be somehow related to what’s valid for CNAME records?
In this case, a sophisticated attacker can get certificates for domains they don’t control by abusing this.