Because they point foo.example.com to AWS. They then let whatever the CNAME is pointing to lapse. Then an attacker registers the lapsed AWS and can now put their content on your trusted domain.
https://aws.amazon.com/blogs/security/threat-tactic-spotligh...
(AWS have since fixed this problem, but it exists on other services.)