Hi, this was sent to me by @brettwilcox via an email and just wanted to pass along:
LdapSignIn module has a security issue where the “cached” ProcessWire password is used indefinitely. When the users password changes in Active Directory, it will not use the new password. This is due to the logic within the module.