Misconfigured AWS API keys led to the exfiltration of a database snapshot containing Cloud WAF customer info.