Cyber.mil serving file downloads using TLS certificate which expired 3 days ago

https://www.cyber.mil/stigs/downloads

Welcome to LWC Communities!

Is there anything inherently insecure about an expired cert other than your browser just complaining about it?
No, but it reflects poorly on the maintainer. Plus, any browser complaint contributes to error fatigue. Users shouldn't just ignore these, and we shouldn't encourage them to ignore them just because we fail at securing our websites.
“No, but it reflects badly because it’s an error, and because it’s an error it contributes to error fatigue, which is bad” is a very verbose way to say that you don’t have an answer.

Your comment history reflects a persistent approach: insulting the person you're replying to.

Please reflect on the site guidelines. https://news.ycombinator.com/newsguidelines.html

Hacker News Guidelines

There is a reason why certs have expiration dates. It's to control the damage after the site owner or someone else in the cert chain messes up. That doesn't mean expired certs are inherently not secure, only that you should still care about it and do your best to avoid using expired certs.
On the contrary, it's a very precise answer.