What else can be considered as a threat to my privacy when I use rotating IP to connect to Electrum server?
[...]
What can make me vulnerable? Please, elaborate.
Basically any information which identifies you. Nor necessarily directly you, but anything which describes a subset of possible entities.
An example would be the script type you use. Bech32 transactions make up a total of less than 10% (estimated; a year ago it was roughly below 7%).
Together with for example the usual quantity you transact with and/or specific timeframes you usually transact, this further reduces the anonymity set.
This could be used with non-bitcoin related pieces of information to make
your profile more specific.
Just as you are being tracked across the internet. Not through your IP address, but through cookies and other specific configurations such as your screen size, color depth of your screen, language, specific browser and/or OS version, etc..
I remember reading (don't know where currently) that such information (a pc/browser configuration) can be used to track one person out of a million. With ~5 million people for example visiting a specific website or using a specific service, your anonymity set could be shrinked to 5.
Obviously this shouldn't be generalized, and i am not saying that you are being tracked or are surfing/transacting with an anonymity set of X, but it's not as easy as changing your IP address to not get tracked / identified.
This applies to an electrum server as well as browsing the web.
Using Tor also doesn't guarantee you
perfect privacy. People doing illegal stuff there get caught relatively often. Sometimes it is because of the link to their real identity (e.g. cash flow) but sometimes it's because of their behavior and/or "wrong" configuration.
The whole privacy- and anonymity aspect is not as easy as one might think.