This paper presents a comprehensive analysis of South Korea's cyber threat landscape and internet-exposed asset vulnerabilities by integrating Shodan EASM scan data (April 11, 2026) with CYFIRMA threat intelligence. The scan identified over 37.17 million exposed ports, with 538,230 hosts vulnerable under CISA KEV and 1,820,536 under VulnCheck KEV. Critical findings include 4,321 ICS/OT devices directly exposed to the internet, 25,742 unauthenticated databases, 1,171 BlueKeep-unpatched systems, and 50 hosts with confirmed remote code execution vectors. North Korea-linked APT groups including Lazarus Group, Kimsuky, and APT37, alongside ransomware operators Qilin and LockBit, are actively exploiting these vulnerabilities. This paper proposes a tiered security roadmap with immediate (0-30 days), short-term (1-6 months), and long-term (6+ months) countermeasures, along with sector-specific priority action matrices.