They are using the certificate of the second level domain (drivethrurpg.com), but the URL is a third level domain (graphics.drivethrurpg.com), since the URLs are different, the browser is sending the alarm. Since it is a subdomain of the certificated one, there is nothing to worry about, probably.
That 'potentially malicious' stuff is just a standard message, there shouldn't really be anything to worry about, because the site in question is their own subdomain.
Another reason to never use or trust DTRPG because they crash your boot sectors and spy on your web surfing habbits.
They have however found out that WW buyers like more fetish material than a D&D buyer, who just looks at this all day long: www.giantitp.com/cgi-bin/GiantITP/ootscript
While I agree.. there "shouldn't" be a problem..there also shouldn't be this problem either. Obviously they are making changes that effect others will very little testing. Disarming people because you assume there is no problem is not the proper recourse since you will not be personally fixing any problems that "could" creep up.
It is a problem and can cause larger problems "if" in the wrong hands.
*Morris: Sorry about the post in General.. waking up and get 2 different systems alarming me of a security issue I kind of get a little.. edgy*