I think, in a way, they are.
The point he's making, in my opinion, is that while farming rats to kill them is useless, farming vulnerabilities is not. There's no real use in advancing our knowledge of rat slaughter, we know how to do that pretty well already, and these rat farmers are indeed gaming the system.
Researchers aren't necessarily injecting bugs in the system unscrupulously, but even if they were, would it be a bad thing? The nature of security is such that bug farming would probably help move the problem forward. The science of mitigating threats is far more complicated than that of killing rats. So manufacturing vulnerabilities will advance our understanding of computer security.
It's a loose metaphor, but I see it.