SolarWinds: NERC Advisory
The North American Electric Reliability Corp. (NERC) has issued an advisory noting that the SolarWinds supply chain attack "poses a potential threat" to elements of the power sector. NERC is also asking utilities and other power companies to respond to a list of questions on the level of exposure their systems have to the SolarWinds campaign.
Even if you're using SolarWinds on an isolated network, you may still have impacted versions as updates would have passed file integrity checks before deployment there. The list of impacted versions continues to increase; it's prudent to locate all instances of the product and disable them until new clean versions can be installed, or replace SolarWinds entirely.