Few easy ones as well:
1) Terminating instances that had ephemeral disks with stuff you needed while thinking the EBS volumes would remain
2) Leaving NAT gateways lying around or ELBs that do nothing and have no instances attached.
3) Public S3 buckets - arguably the most common one that can lead to security incidents
4) Debugging security groups/Network ACLs and straight up break networking for something without knowing it. Reverse of that would be you want to fix something quickly and open 0.0.0.0/0 to everyone and never get around to tightening up the firewall later on.