A security researcher disclosed five cross-tenant vulnerabilities in Azure API Connections that allow attackers to fully compromise other tenants' connections and access backend services like Key Vaults and SQL databases, earning $200,000 in bug bounties. The flaws stem from insecure architecture in Azure Logic Apps' API Connection system, which can be exploited through ARM REST API endpoints to trick the service into operating on victim connections.