What's the incentive for Google in doing this?
Google's goals are so grand they see things like securing software and getting faster broadband everywhere as things worth doing. I've been reading their blog since launch and the team is very skilled, professional and interested in proving theory with actual exploits.
http://googleonlinesecurity.blogspot.de/2014/07/announcing-p...
The headline is kinda silly in the sense that if Project Zero focuses on any software in the world, they'll most likely find exploitable vulnerabilities. With Kaspersky the ridiculous thing is that they have stuff compiled without /GS, which e.g. since VS2005 has required you to actively disable it, as it's on by default.