Server Compromised - what is the best course of action to prevent a re-occurance?

SYSTEM INFORMATION
OS type and version Debian Linux 13
Virtualmin version 8.1.0 Professional

Over the past weekend (July 25th-26th), I got a notice from my Joomla sites that a file (index.php) had been modified on several sites on my Virtualmin server. Due to work timing, I didn’t get to dig into it until today, when I noticed I was getting 403 Access Denied errors when trying to log into the Joomla sites. Doing a check in Virtualmin, I was able to whack the .htaccess files and gain access, at which point I saw files and directories added to my site’s file structures. I quickly deleted the sites, then restored from a backup from before the compromise.

After this was done, I took a look at ALL my sites hosted on Virtualmin, and found several more that had the same files / folders added - some were simple proxy sites with no content, others were plain HTML sites.

Before I whack and restore them, I wanted to check - should I be doing anything with these file or sites, to find out how they were compromised? If there’s a weakness in my server, I’d like to patch it, but I am not sure how to find out how they got access in the first place - via Joomla, WP, Apache, or something else.

Not sure if helps but there was a recent topic on Joomla and site being compromised.
https://forum.virtualmin.com/t/possible-unauthorized-access-to-my-server/137460

That’s a lead, thank you. Everything is up to date on all my Joomla sites, but at least one of them was compromised back in June - it’s likely they had access for a while, but didn’t take action until this past weekend.

Given the first thing most likely to happen is for the attacker to install more back doors, I’ll revert everything I can to before June, and work from there.