Help, sites being repeatedly hacked

I have a couple of sites being repeatedly hacked. They are using a particular open source CMS. I have upgraded the CMS and implemented what I thought was a fairly restrictive htaccess configuration. Somehow, the attackers are getting through.

What info is available to tell me how these sites are being hacked? I’d like to be able to provide info to the CMS developers to stop these attacks.

See #APY-71526-186 for some info, I can provide info on the other site privately.

The other thing, I keep getting emails from supposed security monitoring companies, even phone calls. Are these folks legit or are they part of the scam? I got two from the most recent hack from different companies. It has me wondering…

Thanks,
Tim

sounds like part of the scam.

Mohit, Praveen, and Tanmaya will need to aid in this as it is linux servers.