So DNS should be open to MITM attackers?

Even with DNSSEC, it still is. Example: https://blog.cloudflare.com/de-tld-outage-dnssec/

Did you read the article? It's saying that DNSSEC as an implementation to prevent MITM is flawed; other solutions that protect against MITM are proposed.