Ensure that security groups does not have TCP port 4333 or 3306 for MySQL open to the public.
While some ports such as HTTP and HTTPS are required to be open to the public to function properly, more sensitive services such as MySQL should be restricted to known IP addresses.
Restrict TCP port 4333 or 3306 for MySQL to known IP addresses