CAs need to go away. They’re untrustworthy and their inclusion in browsers and OSes seems largely unregulated.
But until there’s a widely adopted alternative (DANE, peer-to-peer trust, Web of Trust 2.0?), we’re stuck maintaining vigilance within this system. And unfortunately, the shorter cert lifecycles and increasing complexity only make that harder.