Hackers....

Two domains on Web16 have had their conf file renamed/removed - is that something that indicates the server itself is compromised?

If not, how would hackers can access to files at that level?
Is it possible there is a file on one of my domains that is giving them this level of access?

I have noticed that others hosting companies are requiring the upgrade to PHP 5.4 - should we pursue this as well?

It’s not due to hack, conf file was renamed automatically due to some bad syntax in them after H-sphere upgrade.

I have noticed that others hosting companies are requiring the upgrade to PHP 5.4 - should we pursue this as well?

We would like to update you that PHP versions upto 5.5 are also available after H-sphere upgrade. You can now choose any of the PHP version as per requirement.