You should look into upgrading to 1.5.9 for all your 1.0 sites. Check all your logs to try and find out HOW they got in. AFAIK there are no known security holes atm.